---
cve: "CVE-2015-6538"
severity: "LOW"
cvss: 3.1
epss: "1.9%"
vendor: "n/a"
kev: false
exploited: false
published: "2015-12-27 19:59:01"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T03:01:24+02:00"
---

# CVE-2015-6538

> 3.1 LOW

## Beschreibung

The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.

## Referenzen

- <http://www.epiphanyhealthdata.com/blog/certresponse>
- <https://www.kb.cert.org/vuls/id/630239>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2015-6538) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
