Lucene search

K
cveCiscoCVE-2018-0414
HistoryOct 05, 2018 - 2:29 p.m.

CVE-2018-0414

2018-10-0514:29:00
CWE-611
cisco
web.nvd.nist.gov
32
cisco
secure access
control server
vulnerability
xml
remote attack
cve-2018-0414

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

40.5%

A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file.

Affected configurations

Nvd
Node
ciscosecure_access_control_server_solution_engineRange<5.8
OR
ciscosecure_access_control_server_solution_engineMatch5.8-
OR
ciscosecure_access_control_server_solution_engineMatch5.8p1
OR
ciscosecure_access_control_server_solution_engineMatch5.8p2
OR
ciscosecure_access_control_server_solution_engineMatch5.8p3
OR
ciscosecure_access_control_server_solution_engineMatch5.8p4
OR
ciscosecure_access_control_server_solution_engineMatch5.8p5
OR
ciscosecure_access_control_server_solution_engineMatch5.8p6
OR
ciscosecure_access_control_server_solution_engineMatch5.8p7
OR
ciscosecure_access_control_server_solution_engineMatch5.8p8
OR
ciscosecure_access_control_server_solution_engineMatch5.8p9
VendorProductVersionCPE
ciscosecure_access_control_server_solution_engine*cpe:2.3:a:cisco:secure_access_control_server_solution_engine:*:*:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:-:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p1:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p2:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p3:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p4:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p5:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p6:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p7:*:*:*:*:*:*
ciscosecure_access_control_server_solution_engine5.8cpe:2.3:a:cisco:secure_access_control_server_solution_engine:5.8:p8:*:*:*:*:*:*
Rows per page:
1-10 of 111

CNA Affected

[
  {
    "product": "Cisco Secure Access Control Server Solution Engine (ACSE)",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

40.5%

Related for CVE-2018-0414