Critical severity9.8NVD Advisory· Published Dec 27, 2015· Updated Jun 17, 2026
CVE-2015-6538
CVE-2015-6538
Description
The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:ephiphanyheathdata:cardio_server:3.3:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:ephiphanyheathdata:cardio_server:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:ephiphanyheathdata:cardio_server:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:ephiphanyheathdata:cardio_server:4.1:*:*:*:*:*:*:*
- (no CPE)range: 3.3, 4.0, 4.1
Patches
Vulnerability mechanics
References
2- www.epiphanyhealthdata.com/blog/certresponsenvdVendor Advisory
- www.kb.cert.org/vuls/id/630239nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.