CVE-2015-6348
published 2015-10-30CVE-2015-6348: The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass…
PriorityP419medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.37%
68.7th percentile
The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x785-m5vp-jc3c: The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5
ghsa_unreviewed·2022-05-17
CVE-2015-6348 [MEDIUM] GHSA-x785-m5vp-jc3c: The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5
The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page.
Cisco
Cisco Secure Access Control Server Role-Based Access Control Weak Protection Vulnerability
vendor_cisco·2015-10-26·CVSS 4.0
CVE-2015-6348 [MEDIUM] CWE-264 Cisco Secure Access Control Server Role-Based Access Control Weak Protection Vulnerability
Cisco Secure Access Control Server Role-Based Access Control Weak Protection Vulnerability
A vulnerability in the role-based access control (RBAC) implementation of the Cisco Secure Access Control Server (ACS) could allow an authenticated, remote attacker to view system administrator reports and status.
The vulnerability is due to improper RBAC validation when a user accesses the report generation web interface. An attacker could exploit this vulnerability by authenticating as a non-privileged user and navigating to what should be a restricted web page. A successful exploit could allow the attacker to view confidential report and status information about the affected device, including IP addresses and usernames.
Cisco has released software updates that address this vulnerability. Workar
Cisco
Cisco Secure Access Control Server Role-Based Access Control Weak Protection Vulnerability
vendor_cisco
CVE-2015-6348 Cisco Secure Access Control Server Role-Based Access Control Weak Protection Vulnerability
CVE-2015-6348: Cisco Secure Access Control Server Role-Based Access Control Weak Protection Vulnerability
A vulnerability in the role-based access control (RBAC) implementation of the Cisco Secure Access Control Server (ACS) could allow an authenticated, remote attacker to view system administrator reports and status. The vulnerability is due to improper RBAC validation when a user accesses the report generation web interface. An attacker could exploit this vulnerability by authenticating as a non-privileged user and navigating to what should be a restricted web page. A successful exploit could allow the attacker to view confidential report and status information about the affected device, including IP addresses and usernames. Cisco has released software updates that address this vulnerabi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-30
Published