peter bassill · operator
$ cve CVE-2015-2805 JSON

CVE-2015-2805 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS3.03% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2015-06-16
Last modified2026-06-17

Affected (10)

VendorProduct
alcatel-lucentomniswitch 10k
alcatel-lucentomniswitch 6250
alcatel-lucentomniswitch 6400
alcatel-lucentomniswitch 6450
alcatel-lucentomniswitch 6850e
alcatel-lucentomniswitch 6855
alcatel-lucentomniswitch 6860
alcatel-lucentomniswitch 6900
alcatel-lucentomniswitch 9000e
alcatel-lucentomniswitch firmware

Public exploits

SourceTitleDate
exploit-dbAlcatel-Lucent OmniSwitch - Cross-Site Request Forgery2015-06-10

References

→ the Explorer  ·  watch your stack  ·  NVD