Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gm7g-6h7x-rpgr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by sending malicious requests to a targeted system that contain references within XML entities. An exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a DoS condition.

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by sending malicious requests to a targeted system that contain references within XML entities. An exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a DoS condition.

EPSS

Процентиль: 72%
0.00709
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by sending malicious requests to a targeted system that contain references within XML entities. An exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a DoS condition.

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость программного средства для создания отчетов для развернутых средств безопасности Cisco Security Manager, связанная с ошибками ограничения XML-ссылок на внешние объекты, позволяющая нарушителю получить доступ к конфиденциальной информации и вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00709
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-611