CVE-2015-6395: Cisco Prime Service Catalog

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify the configuration via a direct request, aka Bug ID CSCuw48188.

Affected products

  • Cisco Prime Service Catalog: version 10.0(r2)_base only; version 10.0_base only; version 10.1_base only; version 11.0_base only

Published 2015-12-12. Last modified 2026-06-17.