3.5
CVSSv2

CVE-2018-0414

Published: 05/10/2018 Updated: 09/10/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.7 | Impact Score: 3.6 | Exploitability Score: 2.1
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote malicious user to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco secure access control server solution engine 5.8

cisco secure access control server solution engine

Vendor Advisories

A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file An attacker could exploit this vulnerability by convincing t ...