CVE-2015-6346: Cisco Secure Access Control Server

Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Affected products

  • Cisco Secure Access Control Server: version 5.7.0.15 only

Published 2015-10-30. Last modified 2026-06-17.