Lucene search

K
cveCiscoCVE-2011-3317
HistoryMay 02, 2012 - 10:09 a.m.

CVE-2011-3317

2012-05-0210:09:21
CWE-79
cisco
web.nvd.nist.gov
23
cve-2011-3317
xss
cisco secure acs 5.2
remote attackers
web script
html
csctr78192

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

56.9%

Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192.

Affected configurations

Nvd
Node
ciscosecure_access_control_serverMatch5.2
VendorProductVersionCPE
ciscosecure_access_control_server5.2cpe:2.3:h:cisco:secure_access_control_server:5.2:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

56.9%

Related for CVE-2011-3317