The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute commands via a login session, aka Bug ID CSCur27371.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=39192 | Vendor Advisory |
http://www.securitytracker.com/id/1032541 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2015-06-12T14:00:00
Updated: 2016-12-29T18:57:01
Reserved: 2015-01-07T00:00:00
Link: CVE-2015-0768
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-06-12T14:59:00.067
Modified: 2017-01-04T16:03:14.727
Link: CVE-2015-0768
JSON object: View
Redhat Information
No data.
CWE