CVE-2016-1343 describes an XML External Entity (XXE) vulnerability in the XML parser of Cisco Information Server (CIS) 6.2. This critical flaw allows unauthenticated remote attackers to read arbitrary files from the server or trigger a denial of service by exploiting CPU and memory consumption. With a CVSS score of 10.0, the vulnerability is easily exploitable over the network with no user interaction required, leading to complete confidentiality compromise and denial of service. Despite its severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received negligible community discussion or media coverage, indicating a low current exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2_baseCPE matchmatch criteria | cpe:2.3:a:cisco:information_server:6.2_base:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.