CVE-2015-6347: Cisco Secure Access Control Server

Medium severity, CVSS 4.0. EPSS: 1.4% chance of exploitation in the next 30 days.

The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.

Affected products

  • Cisco Secure Access Control Server: version 5.7.0.15 only

Published 2015-10-30. Last modified 2026-06-17.