Vulnslist

find the latest Cisco vulnerabilities

Cisco Information Server XML Parser Denial of Service Vulnerability

cisco-sa-20160428-cis · Medium · Published · Updated

A vulnerability in the default configuration of the XML parser component of Cisco Information Server (CIS) could allow an unauthenticated, remote attacker to access sensitive data or cause excessive consumption of system resources, which could cause a denial of service (DoS) condition on a targeted system. The vulnerability is due to improper handling of XML External Entities (XXE) by the affected software when the software parses XML files. An attacker could exploit this vulnerability by submitting a crafted XML header to the CIS web framework of an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160428-cis

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-1343
Cisco Bug IDsCSCuy39059
CVSS ScoreBase 6.4
Base 6.4 AV:N/AC:L/Au:N/C:P/I:P/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco Information Server (CIS)

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2016-1343 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2016-1343 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2016-1343 Cisco OpenVuln
Cisco Information Server (CIS) CVE-2016-1343 Cisco OpenVuln