Lucene search

K
cveCiscoCVE-2013-1140
HistoryMar 06, 2013 - 1:10 p.m.

CVE-2013-1140

2013-03-0613:10:25
CWE-200
cisco
web.nvd.nist.gov
23
cisco
security
monitoring
analysis
response
system
mars
xml parser
remote attacks
arbitrary files
external entity declaration
entity reference
xxe issue
bug id
cscue55093

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

66.1%

The XML parser in Cisco Security Monitoring, Analysis, and Response System (MARS) allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCue55093.

Affected configurations

Nvd
Node
ciscosecurity_monitoring_analysis_and_response_system
VendorProductVersionCPE
ciscosecurity_monitoring_analysis_and_response_system*cpe:2.3:h:cisco:security_monitoring_analysis_and_response_system:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

66.1%

Related for CVE-2013-1140