CVE-2015-6347
published 2015-10-30CVE-2015-6347: The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.37%
68.7th percentile
The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3j82-49jr-frq8: The Solution Engine in Cisco Secure Access Control Server (ACS) 5
ghsa_unreviewed·2022-05-17
CVE-2015-6347 [MEDIUM] GHSA-3j82-49jr-frq8: The Solution Engine in Cisco Secure Access Control Server (ACS) 5
The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.
Cisco
Cisco Secure Access Control Server Role-Based Access Control URL Lack of Protection Vulnerability
vendor_cisco·2015-10-26·CVSS 4.0
CVE-2015-6347 [MEDIUM] CWE-264 Cisco Secure Access Control Server Role-Based Access Control URL Lack of Protection Vulnerability
Cisco Secure Access Control Server Role-Based Access Control URL Lack of Protection Vulnerability
A vulnerability in the role-based access control (RBAC) implementation of the Cisco Secure Access Control Server (ACS) could allow an authenticated, remote attacker to impact the integrity of the system by modifying dashboard portlets that should be restricted.
The vulnerability is due to improper RBAC validation when a new administrative dashboard or portlet is created. An attacker could exploit this vulnerability by authenticating as a non-privileged user and navigating to what should be a restricted web page. A successful exploit could allow the attacker to create a dashboard or portlet, which should not be allowed.
Cisco has released software updates that address this vulnerability. Wor
Cisco
Cisco Secure Access Control Server Role-Based Access Control URL Lack of Protection Vulnerability
vendor_cisco
CVE-2015-6347 Cisco Secure Access Control Server Role-Based Access Control URL Lack of Protection Vulnerability
CVE-2015-6347: Cisco Secure Access Control Server Role-Based Access Control URL Lack of Protection Vulnerability
A vulnerability in the role-based access control (RBAC) implementation of the Cisco Secure Access Control Server (ACS) could allow an authenticated, remote attacker to impact the integrity of the system by modifying dashboard portlets that should be restricted. The vulnerability is due to improper RBAC validation when a new administrative dashboard or portlet is created. An attacker could exploit this vulnerability by authenticating as a non-privileged user and navigating to what should be a restricted web page. A successful exploit could allow the attacker to create a dashboard or portlet, which should not be allowed. Cisco has released software updates that address this vulner
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-30
Published