CVE-2015-6347: Medium severity cisco secure access control server vulnerability
Published Oct 30, 2015
·Updated
The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.
Affected Software
1 affected component
Cisco Secure Access Control Server=5.7.0.15
Event History
Oct 30, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6347?
CVE-2015-6347 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-6347?
To mitigate CVE-2015-6347, upgrade Cisco Secure Access Control Server to version 5.7(0.16) or later.
3
Who is affected by CVE-2015-6347?
CVE-2015-6347 affects remote authenticated users of Cisco Secure Access Control Server version 5.7(0.15).
4
What is the main impact of CVE-2015-6347?
The main impact of CVE-2015-6347 is the bypassing of role-based access control (RBAC) restrictions.
5
What software versions are vulnerable to CVE-2015-6347?
The vulnerable software version for CVE-2015-6347 is Cisco Secure Access Control Server 5.7(0.15).