CVE-2017-3839
published 2017-02-22CVE-2017-3839: An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote…
PriorityP427medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.55%
72.3th percentile
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_system | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control System XML External Entity Vulnerability
vendor_cisco·2017-02-15·CVSS 4.3
CVE-2017-3839 [MEDIUM] CWE-20 Cisco Secure Access Control System XML External Entity Vulnerability
Cisco Secure Access Control System XML External Entity Vulnerability
A vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system.
The vulnerability is due to improper handling of the XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by submitting a crafted XML header to the affected device web framework.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs1
Cisco
Cisco Secure Access Control System XML External Entity Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3839 Cisco Secure Access Control System XML External Entity Vulnerability
CVE-2017-3839: Cisco Secure Access Control System XML External Entity Vulnerability
A vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to have read access to part of the information stored in the affected system. The vulnerability is due to improper handling of the XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by submitting a crafted XML header to the affected device web framework. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvc04845
GHSA
GHSA-vgvw-m3x5-grc3: An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, r
ghsa_unreviewed·2022-05-13
CVE-2017-3839 [MEDIUM] CWE-611 GHSA-vgvw-m3x5-grc3: An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, r
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96236http://www.securitytracker.com/id/1037836https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs1http://www.securityfocus.com/bid/96236http://www.securitytracker.com/id/1037836https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs1
2017-02-22
Published