CVE-2016-6436
MEDIUMHostScan Engine <3.1.14018 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in HostScan Engine 3.0.08062 through 3.1.14018 in the Cisco Host Scan package, as used in ASA Web VPN, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz14682.
Scores
CVSS v3
6.1
EPSS
0.0025
EPSS Percentile
48.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (23)
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
cisco/hostscan_engine
... and 8 more
Timeline
Published
Oct 06, 2016
Tracked Since
Feb 18, 2026