MEDIUM · 6.5

CVE-2015-5434

HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and for...

Vulnerability Description

HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and forwarding (VRF) hopping."

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
HpJg786A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fd-
HpJg787A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fd Taa-
HpJg788A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fg-
HpJg789A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fg Taa-
HpJg798A Hp Flexfabric 12508E Fabric-
HpJg810Aae Hp Vsr1001 Virtual Services Router 60 Day Evaluation-
HpJh192A Hp 10500 48-Port Gig-T \(Rj45\) Se-
HpJh196A Hp 10500 2-Port 100Gbe Cfp Ec-
HpJc072B Hp 12500 Main Processing Unit-
HpJc085A Hp A12518 Switch Chassis-
HpJc086A Hp A12508 Switch Chassis-
HpJc124A Hp A9508 Switch Chassis-
HpJc124B Hp 9505 Switch Chassis-
HpJc125A Hp A9512 Switch Chassis-
HpJc125B Hp 9512 Switch Chassis-
HpJc474A Hp A9508-V Switch Chassis-
HpJc474B Hp 9508-V Switch Chassis-
HpJc611A Hp 10508-V Switch Chassis-
HpJc612A Hp 10508 Switch Chassis-
HpJc613A Hp 10504 Switch Chassis-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-5434?

CVE-2015-5434 is a vulnerability with a CVSS score of 6.5 (MEDIUM). HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cause a denial of service via "Virtual routing and for...

How severe is CVE-2015-5434?

CVE-2015-5434 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-5434?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Jg786A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fd, Hp Jg787A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fd Taa, Hp Jg788A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fg, Hp Jg789A Hp Flexfabric 12500 4-Port 100Gbe Cfp Fg Taa, Hp Jg798A Hp Flexfabric 12508E Fabric.