CVE-2015-6348
Cisco Secure Access Control Server 5.7(0.15) - Authenticated RBAC Bypass via Report-Generation Web Interface
Title source: llmDescription
The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033970
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151023-acs_rbac1
Scores
EPSS
0.0137
EPSS Percentile
69.0%
Details
CWE
CWE-264
Status
published
Products (1)
cisco/secure_access_control_server
5.7.0.15
Published
Oct 30, 2015
Tracked Since
Feb 18, 2026