First published: Wed Jun 17 2015(Updated: )
Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vortex on Cloud Portal appliances allows man-in-the-middle attackers to modify data via unspecified vectors, aka Bug ID CSCuh19683.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Service Catalog | =9.4.1_vortex |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4190 is considered a high severity vulnerability due to its potential impact on data integrity and confidentiality.
To fix CVE-2015-4190, it is recommended to apply the latest security patches provided by Cisco for the affected version of Cisco Prime Service Catalog.
Organizations using Cisco Prime Service Catalog version 9.4.1_vortex on Cloud Portal appliances are affected by CVE-2015-4190.
CVE-2015-4190 allows man-in-the-middle attackers to modify data exchanged between users and the Cloud Portal.
Even with a firewall, CVE-2015-4190 remains a risk if the underlying vulnerability is not patched, as firewalls do not prevent man-in-the-middle attacks.