Lucene search

K
cveCiscoCVE-2015-6395
HistoryDec 12, 2015 - 11:59 a.m.

CVE-2015-6395

2015-12-1211:59:00
CWE-264
cisco
web.nvd.nist.gov
30
cve-2015-6395
cisco
prime service catalog
bug id cscuw48188
access restriction
remote attack

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

54.6%

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.

Affected configurations

Nvd
Node
ciscoprime_service_catalogMatch10.0\(r2\)_base
OR
ciscoprime_service_catalogMatch10.0_base
OR
ciscoprime_service_catalogMatch10.1_base
OR
ciscoprime_service_catalogMatch11.0_base
VendorProductVersionCPE
ciscoprime_service_catalog10.0(r2)_basecpe:2.3:a:cisco:prime_service_catalog:10.0\(r2\)_base:*:*:*:*:*:*:*
ciscoprime_service_catalog10.0_basecpe:2.3:a:cisco:prime_service_catalog:10.0_base:*:*:*:*:*:*:*
ciscoprime_service_catalog10.1_basecpe:2.3:a:cisco:prime_service_catalog:10.1_base:*:*:*:*:*:*:*
ciscoprime_service_catalog11.0_basecpe:2.3:a:cisco:prime_service_catalog:11.0_base:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

54.6%

Related for CVE-2015-6395