SB2021070810 - Missing XML Validation in Cisco Web Security Appliance
Published: July 8, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing XML Validation (CVE-ID: CVE-2021-1359)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input for the web interface. A remote authenticated attacker can upload specially crafted XML configuration files to execute arbitrary commands on the underlying operating system and elevate privileges to root.
Remediation
Install update from vendor's website.