Lucene search

K
cveCiscoCVE-2015-6349
HistoryOct 30, 2015 - 10:59 a.m.

CVE-2015-6349

2015-10-3010:59:07
CWE-79
cisco
web.nvd.nist.gov
25
cisco
secure access control server
acs
xss
cross-site scripting
vulnerability
cve-2015-6349
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

49.1%

Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Affected configurations

Nvd
Node
ciscosecure_access_control_serverMatch5.7.0.15
VendorProductVersionCPE
ciscosecure_access_control_server5.7.0.15cpe:2.3:a:cisco:secure_access_control_server:5.7.0.15:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

49.1%

Related for CVE-2015-6349