CVE-2017-3838: Cisco Secure Access Control System

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Known Affected Releases: 5.8(2.5).

Affected products

  • Cisco Secure Access Control System: version 5.8(2.5) only

Published 2017-02-22. Last modified 2026-06-17.