6.5
CVSSv2

CVE-2015-6417

Published: 12/12/2015 Updated: 28/11/2016
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and previous versions does not always use RBAC for backend database access, which allows remote authenticated users to read or write to database entries via (1) the GUI or (2) a crafted HTTP request, aka Bug ID CSCuv87025.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco videoscape distribution suite service manager 3.4.0

cisco videoscape distribution suite service manager 3.2.0

cisco videoscape distribution suite service manager 3.0.0

cisco videoscape distribution suite service manager 3.1.0

cisco videoscape distribution suite service manager 3.3.0

Vendor Advisories

A vulnerability in the role-based access control (RBAC) for certain users of the Cisco Videoscape Distribution Suite Service Manager (VDS-SM) could allow an authenticated, remote attacker read and write access to an internal database that contains sensitive information The vulnerability is due to lack of implementation of RBAC where authenticatio ...