CVE-2015-4225
published 2015-06-27CVE-2015-4225: Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which…
PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.03%
79.0th percentile
Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-37rg-q6m8-6h7g: Cisco Application Policy Infrastructure Controller (APIC) 1
ghsa_unreviewed·2022-05-17
CVE-2015-4225 [MEDIUM] GHSA-37rg-q6m8-6h7g: Cisco Application Policy Infrastructure Controller (APIC) 1
Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.
Cisco
Cisco Application Policy Infrastructure Controller Unauthorized Access Vulnerability
vendor_cisco·2015-06-26·CVSS 4.0
CVE-2015-4225 [MEDIUM] CWE-264 Cisco Application Policy Infrastructure Controller Unauthorized Access Vulnerability
Cisco Application Policy Infrastructure Controller Unauthorized Access Vulnerability
A vulnerability in the role-based access control (RBAC) of the Cisco Application Policy Infrastructure Controller (Cisco APIC) could allow an authenticated, remote attacker to have read access to certain information stored in the affected system.
The vulnerability is due to improper handling of RBAC for health scoring. An attacker could exploit this vulnerability to gain access to information on the affected system.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted system. This access requirement reduces the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-27
Published