CVE-2015-0768

EUVD-2015-0781
The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute commands via a login session, aka Bug ID CSCur27371.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
ciscoprime_network_control_system
2.1\(0.0.85\)
ciscoprime_network_control_system
2.2\(0.0.58\)
ciscoprime_network_control_system
2.2\(0.0.69\)
𝑥
= Vulnerable software versions
Common Weakness Enumeration