CVE Vulnerabilities

CVE-2015-6395

Published: Dec 12, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.

Affected Software

NameVendorStart VersionEnd Version
Prime_service_catalogCisco10.0(r2)_base (including)10.0(r2)_base (including)
Prime_service_catalogCisco10.0_base (including)10.0_base (including)
Prime_service_catalogCisco10.1_base (including)10.1_base (including)
Prime_service_catalogCisco11.0_base (including)11.0_base (including)

References