CVE-2015-0580 describes multiple SQL injection vulnerabilities in the ACS View reporting interface of Cisco Secure Access Control System (ACS) versions prior to 5.5 patch 7. Authenticated remote administrators can exploit these flaws by sending crafted HTTPS requests, leading to the execution of arbitrary SQL commands. With a CVSS score of 6.5, this vulnerability has a network attack vector, low attack complexity, and can result in partial compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, though it has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.5.0.46CPE matchmatch criteria | cpe:2.3:a:cisco:secure_access_control_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.