CVE-2017-3840: Cisco Secure Access Control System

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. More Information: CSCvc04849. Known Affected Releases: 5.8(2.5).

Affected products

  • Cisco Secure Access Control System: version 5.8(2.5) only

Published 2017-02-22. Last modified 2026-06-17.