CVE-2015-6362
published 2015-11-10CVE-2015-6362: The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.38%
69.1th percentile
The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | connected_grid_network_management_system | — | — |
| cisco | connected_grid_network_management_system | — | — |
| cisco | connected_grid_network_management_system | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Connected Grid Network Management System Privilege Escalation Vulnerability
vendor_cisco·2015-11-09·CVSS 4.0
CVE-2015-6362 [MEDIUM] CWE-264 Cisco Connected Grid Network Management System Privilege Escalation Vulnerability
Cisco Connected Grid Network Management System Privilege Escalation Vulnerability
A vulnerability in the web GUI of Cisco Connected Grid Network Management System could allow an authenticated, remote attacker to perform limited configuration changes while logged in as a user having the Monitor-Only role.
The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the related configuration pages on the web interface and submitting the changes. An exploit could allow the attacker to make unauthorized modifications to the targeted system.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https:/
Cisco
Cisco Connected Grid Network Management System Privilege Escalation Vulnerability
vendor_cisco
CVE-2015-6362 Cisco Connected Grid Network Management System Privilege Escalation Vulnerability
CVE-2015-6362: Cisco Connected Grid Network Management System Privilege Escalation Vulnerability
A vulnerability in the web GUI of Cisco Connected Grid Network Management System could allow an authenticated, remote attacker to perform limited configuration changes while logged in as a user having the Monitor-Only role. The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the related configuration pages on the web interface and submitting the changes. An exploit could allow the attacker to make unauthorized modifications to the targeted system. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCuw42640
GHSA
GHSA-wh7v-9p3v-c89w: The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3
ghsa_unreviewed·2022-05-17
CVE-2015-6362 [MEDIUM] GHSA-wh7v-9p3v-c89w: The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3
The web GUI in Cisco Connected Grid Network Management System (CG-NMS) 3.0(0.35) and 3.0(0.54) allows remote authenticated users to bypass intended access restrictions and modify the configuration by leveraging the Monitor-Only role, aka Bug ID CSCuw42640.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-10
Published