CVE-2015-6395
published 2015-12-12CVE-2015-6395: Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the…
PriorityP336medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.51%
71.6th percentile
Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_service_catalog | — | — |
| cisco | prime_service_catalog | — | — |
| cisco | prime_service_catalog | — | — |
| cisco | prime_service_catalog | — | — |
| cisco | prime_service_catalog | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Service Catalog Web Interface Unauthorized Access Vulnerability
vendor_cisco·2015-12-08·CVSS 6.5
CVE-2015-6395 [MEDIUM] CWE-264 Cisco Prime Service Catalog Web Interface Unauthorized Access Vulnerability
Cisco Prime Service Catalog Web Interface Unauthorized Access Vulnerability
A vulnerability in the web interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to perform limited configuration changes.
The vulnerability is due to missing access controls in some of the web pages that allow configuration changes. An attacker could exploit this vulnerability by accessing the URLs of the affected web pages directly. A successful exploit could allow the attacker to submit a configuration change to the targeted system.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/Ci
Cisco
Cisco Prime Service Catalog Web Interface Unauthorized Access Vulnerability
vendor_cisco
CVE-2015-6395 Cisco Prime Service Catalog Web Interface Unauthorized Access Vulnerability
CVE-2015-6395: Cisco Prime Service Catalog Web Interface Unauthorized Access Vulnerability
A vulnerability in the web interface of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to perform limited configuration changes. The vulnerability is due to missing access controls in some of the web pages that allow configuration changes. An attacker could exploit this vulnerability by accessing the URLs of the affected web pages directly. A successful exploit could allow the attacker to submit a configuration change to the targeted system. Cisco has not released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCuw48188
GHSA
GHSA-m97x-rfxh-9ppm: Cisco Prime Service Catalog 10
ghsa_unreviewed·2022-05-17
CVE-2015-6395 [MEDIUM] GHSA-m97x-rfxh-9ppm: Cisco Prime Service Catalog 10
Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-12-12
Published