CVE-2015-4225

medium

Description

Cisco Application Policy Infrastructure Controller (APIC) 1.0(1.110a) and 1.0(1e) on Nexus 9000 devices does not properly implement RBAC health scoring, which allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuq77485.

References

http://www.securitytracker.com/id/1032735

http://www.securityfocus.com/bid/75433

http://tools.cisco.com/security/center/viewAlert.x?alertId=39529

Details

Source: Mitre, NVD

Published: 2015-06-27

Updated: 2016-12-29

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium