PT-2015-4873 · Cisco · Cisco Prime Network Control System

Published

2015-06-12

·

Updated

2017-01-04

·

CVE-2015-0768

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco Prime Network Control System versions 2.1(0.0.85) through 2.2(0.0.69)
Description The issue is related to the Device Work Center component, which does not properly implement AAA roles. This allows remote authenticated users to bypass intended access restrictions and execute commands via a login session.
Recommendations For versions 2.1(0.0.85) through 2.2(0.0.69), update to a version that properly implements AAA roles to prevent unauthorized access and command execution.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0768

Affected Products

Cisco Prime Network Control System