The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute commands via a login session, aka Bug ID CSCur27371.
                
            References
                    | Link | Resource | 
|---|---|
| http://tools.cisco.com/security/center/viewAlert.x?alertId=39192 | Vendor Advisory | 
| http://www.securitytracker.com/id/1032541 | Third Party Advisory VDB Entry | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Information
                Published : 2015-06-12 07:59
Updated : 2017-01-04 08:03
NVD link : CVE-2015-0768
Mitre link : CVE-2015-0768
JSON object : View
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
Products Affected
                cisco
- prime_network_control_system


