CVE-2015-0768: Medium severity Cisco Prime Network Control System vulnerability
The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute commands via a login session, aka Bug ID CSCur27371.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0768?
CVE-2015-0768 has a High severity rating due to its potential for unauthorized command execution.
How do I fix CVE-2015-0768?
To fix CVE-2015-0768, update your Cisco Prime Network Control System to a version that includes the necessary security patches.
What systems are affected by CVE-2015-0768?
CVE-2015-0768 affects Cisco Prime Network Control System versions 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69).
What kind of attack does CVE-2015-0768 facilitate?
CVE-2015-0768 allows remote authenticated users to bypass access restrictions and execute commands.
Who is responsible for fixing CVE-2015-0768?
Owners of affected Cisco Prime Network Control System installations are responsible for applying the updates to mitigate CVE-2015-0768.