CVE-2015-6300
published 2015-09-20CVE-2015-6300: Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash)…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.59%
72.8th percentile
Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmh7-v95w-mh6p: Cisco Secure Access Control Server (ACS) Solution Engine 5
ghsa_unreviewed·2022-05-17
CVE-2015-6300 [MEDIUM] CWE-20 GHSA-gmh7-v95w-mh6p: Cisco Secure Access Control Server (ACS) Solution Engine 5
Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.
Cisco
Cisco Secure Access Control Server SSH Login Denial of Service Vulnerability
vendor_cisco·2015-09-18·CVSS 4.0
CVE-2015-6300 [MEDIUM] CWE-20 Cisco Secure Access Control Server SSH Login Denial of Service Vulnerability
Cisco Secure Access Control Server SSH Login Denial of Service Vulnerability
A vulnerability in the Secure Shell (SSH) feature of the Cisco Secure Access Control Server (ACS) could allow an authenticated, remote attacker to cause a partial denial of service (DoS) condition due to the SSH screen process unexpectedly terminating.
The vulnerability is due to improper input validation of user commands entered at the command line interface (CLI) or GUI. An attacker could exploit this vulnerability by logging into the affected device and executing crafted user commands. An exploit could allow the attacker to cause a partial DoS due to the SSH screen processes unexpectedly terminating. That SSH connection is then lost and the user must log in and authenticate again.
Cisco has confirmed the vul
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-20
Published