CVE-2016-1343
critical
CVSS v3
10.0
CVSS v2
6.4
VIR risk
10.0
Description
The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuy39059.
Predictions
Exploit likelihood
98%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160428-cis
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | information_server | 6.2_base | |
References
Verify integrity in audit chain (admin only). AS-IS.