MEDIUM · 6.8

CVE-2015-2805

Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, ...

Vulnerability Description

Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
Alcatel-LucentOmniswitch Firmware<= 6.4.5.r02
Alcatel-LucentOmniswitch 10KAll versions
Alcatel-LucentOmniswitch 6250All versions
Alcatel-LucentOmniswitch 6400All versions
Alcatel-LucentOmniswitch 6450All versions
Alcatel-LucentOmniswitch 6850EAll versions
Alcatel-LucentOmniswitch 6855All versions
Alcatel-LucentOmniswitch 6860All versions
Alcatel-LucentOmniswitch 6900All versions
Alcatel-LucentOmniswitch 9000EAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2805?

CVE-2015-2805 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, ...

How severe is CVE-2015-2805?

CVE-2015-2805 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2805?

Check the references section above for vendor advisories and patch information. Affected products include: Alcatel-Lucent Omniswitch Firmware, Alcatel-Lucent Omniswitch 10K, Alcatel-Lucent Omniswitch 6250, Alcatel-Lucent Omniswitch 6400, Alcatel-Lucent Omniswitch 6450.