CVE-2015-6395

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
ciscoprime_service_catalog
10.0\(r2\)_base
ciscoprime_service_catalog
10.0_base:_base
ciscoprime_service_catalog
10.1_base:_base
ciscoprime_service_catalog
11.0_base:_base
𝑥
= Vulnerable software versions
Common Weakness Enumeration