XML injection in Cisco Secure Access Control System (ACS) - CVE-2017-3839
Published: February 15, 2017 / Updated: February 17, 2017
Cisco Secure Access Control System (ACS)
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient sanitization of user-supplied data passed in Cisco Secure Access Control System (ACS) when parsing XML files. A remote attacker can send a specially crafted XML file and obtain potentially sensitive information.