Vulnerability Name: | CVE-2015-7819 (CCN-105718) | ||||||||
Assigned: | 2015-10-23 | ||||||||
Published: | 2015-10-23 | ||||||||
Updated: | 2015-11-12 | ||||||||
Summary: | The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-255 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-7819 Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-15-552/ Source: XF Type: UNKNOWN ibm-snsc-cve20157819-info-disc(105718) Source: CONFIRM Type: Vendor Advisory https://support.lenovo.com/us/en/product_security/len_2015_074 Source: CCN Type: IBM Security Bulletin 5098761 (System Networking Switch Center) Multiple vulnerabilities affect IBM System Networking Switch Center (CVE-2015-7817, CVE-2015-7818, CVE-2015-7819, CVE-2015-7820) Source: CCN Type: ZDI-15-552 IBM System Networking Switch Center DB Service Remote Elevation of Privilege Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |