CVE-2016-1343

CRITICAL

Cisco Information Server 6.2 - SSRF

Title source: llm
STIX 2.1

Description

The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuy39059.

References (1)

Core 1
Core References

Scores

CVSS v3 10.0
EPSS 0.0157
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H

Details

Status published
Products (1)
cisco/information_server 6.2_base
Published Apr 30, 2016
Tracked Since Feb 18, 2026