cisco-sa-20170215-acs

Cisco Secure Access Control System Cross-Site Scripting Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of a user-supplied value. An attacker may be able to exploit this vulnerability by intercepting the user packets and injecting malicious code. There are no workarounds that address this vulnerability.