SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-0533

Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary…

MEDIUM 4.3EPSS 28.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 28.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
28.79% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
cisco/acs for windows · cisco/acs solution engine · cisco/user changeable password
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.