4.3
CVSSv2

CVE-2013-1140

Published: 06/03/2013 Updated: 06/03/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The XML parser in Cisco Security Monitoring, Analysis, and Response System (MARS) allows remote malicious users to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCue55093.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco security monitoring analysis and response system

Vendor Advisories

A vulnerability in the configuration of the XML parser of the Cisco Security Monitoring, Analysis and Response System (MARS) could allow an unauthenticated, remote attacker to have "read" access to part of information stored in the affected system The vulnerability is due to improper handling of XML External Entity (XXE) when parsing an XML file ...