PatchSiren cyber security CVE debrief
CVE-2017-3838 Cisco CVE debrief
CVE-2017-3838 is a medium-severity DOM-based cross-site scripting flaw in Cisco Secure Access Control System (ACS). According to the CVE/NVD record, an unauthenticated remote attacker could trigger XSS in the web interface and affect a user of the system. The record lists Cisco Secure Access Control System 5.8(2.5) as the known affected release and classifies the weakness as CWE-79.
- Vendor
- Cisco
- Product
- Secure Access Control System
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-22
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-22
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for Cisco Secure Access Control System deployments, especially systems running the affected 5.8(2.5) release and any environment where users access the ACS web interface.
Technical summary
The vulnerability is a DOM-based XSS issue in the ACS web interface. NVD lists the attack vector as network reachable, with no authentication required, but with user interaction required and a changed scope. The recorded CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating that successful abuse could expose or alter browser-side content for the interacting user.
Defensive priority
Medium. The issue is remotely reachable and requires no attacker authentication, but it does require user interaction and the recorded impact is limited to low confidentiality and integrity effects. Prioritize remediation if the ACS web interface is exposed to users or administrators.
Recommended defensive actions
- Confirm whether Cisco Secure Access Control System 5.8(2.5) is deployed anywhere in your environment.
- Follow Cisco's vendor advisory guidance for remediation and update to a non-affected release if available.
- Restrict access to the ACS web interface to trusted administrative networks only.
- Treat unexpected links, crafted URLs, and unusual web interface behavior as potential XSS indicators.
- Review browser-side protections and security controls used by administrators accessing the ACS interface.
Evidence notes
This debrief is based only on the supplied CVE/NVD corpus and referenced Cisco advisory links. The record states: unauthenticated remote attacker, DOM-based XSS, affected release 5.8(2.5), and CWE-79. Published date used here is the CVE/NVD published timestamp of 2017-02-22T02:59:00.480Z. The modified timestamp is record-maintenance context only and is not treated as the issue date.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3838 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3838
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3838 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3838
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.