cisco-sa-20170215-acs1: Cisco Secure Access Control System XML External Entity Vulnerability
Published Feb 15, 2017
·Updated
Affected Software
1 affected component
Cisco Secure Access Control System
Event History
Feb 15, 2017
Advisory Published
04:00 PM
Data Sourced
04:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of cisco-sa-20170215-acs1?
The severity of cisco-sa-20170215-acs1 is classified as medium with a CVSS score of 4.3.
2
What type of vulnerability is cisco-sa-20170215-acs1?
cisco-sa-20170215-acs1 is categorized as an XML External Entity (XXE) vulnerability.
3
How do I fix cisco-sa-20170215-acs1?
To mitigate cisco-sa-20170215-acs1, update your Cisco Secure Access Control System to the appropriate version as recommended by Cisco.
4
Which product is affected by cisco-sa-20170215-acs1?
The affected product is the Cisco Secure Access Control System.
5
Is user interaction required for cisco-sa-20170215-acs1 exploitation?
No, user interaction is not required for the exploitation of cisco-sa-20170215-acs1.