Known vulnerabilities in Cisco Secure Access Control System (ACS)
Vendor:
Cisco Systems, Inc
Software:
Cisco Secure Access Control System (ACS)
Software CPE:
cpe:2.3:a:cisco_systems:cisco_secure_access_control_system_acs:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU9510 - Exposure of sensitive information to an unauthorized actor CVE-2017-12354 |
CWE-200 | Low | - | 29.11.2017 |
SB2017120111 |
||
| #VU5859 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2017-3838 |
CWE-79 | Low | - | 15.02.2017 |
SB2017021705 |
||
| #VU5860 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2017-3840 |
CWE-79 | Low | - | 15.02.2017 |
SB2017021705 |
||
| #VU5861 - Exposure of sensitive information to an unauthorized actor CVE-2017-3841 |
CWE-200 | Low | - | 15.02.2017 |
SB2017021705 |
||
| #VU5862 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2017-3839 |
CWE-611 | Medium | - | 15.02.2017 |
SB2017021705 |