Vulnerability Details CVE-2015-6397
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2015-6397
-
cpe:2.3:h:cisco:rv110w_wireless-n_vpn_firewall:-
-
cpe:2.3:h:cisco:rv130w_wireless-n_multifunction_vpn_router:-
-
cpe:2.3:h:cisco:rv215w_wireless-n_vpn_router:-
-
cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:-
-
cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:1.1.0.9
-
cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:1.2.0.10
-
cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:1.2.0.9
-
cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:1.2.1.4
-
cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:1.2.2.8
-
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:-
-
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.0.21
-
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.1.3
-
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.2.7
-
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.2.99
-
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.3.54
-
cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.3.55
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:-
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.1.0.5
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.1.0.6
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.2.0.14
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.2.0.15
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.2.2.8
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.3.0.7
-
cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.3.1.7