CVE-2017-3839: Cisco Secure Access Control System

Medium severity, CVSS 4.3. EPSS: 1.6% chance of exploitation in the next 30 days.

An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5).

Affected products

  • Cisco Secure Access Control System: version 5.8(2.5) only

Published 2017-02-22. Last modified 2026-06-17.