XML External Entity Vulnerability in Cisco Prime Data Center Network Manager
CVE-2013-5490
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 23 September 2013
Summary
The vulnerability in Cisco Prime Data Center Network Manager stems from the improper handling of XML External Entity declarations, which allows remote attackers to access sensitive arbitrary text files. This issue can be exploited through specially crafted XML input, potentially leading to unauthorized information disclosure. The affected versions prior to 6.2(1) are particularly susceptible, highlighting the importance of timely updates to mitigate risks associated with XML processing.
References
Timeline
Vulnerability published
Vulnerability Reserved