4.3
CVSSv2

CVE-2015-2804

Published: 16/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware prior to 6.6.4.309.R01 and 6.6.5.x prior to 6.6.5.80.R02 generates weak session identifiers, which allows remote malicious users to hijack arbitrary sessions via a brute force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

alcatel-lucent omniswitch_firmware

Exploits

During a penetration test, RedTeam Pentesting discovered a vulnerability in the management web interface of an Alcatel-Lucent OmniSwitch 6450 This interface uses easily guessable session IDs, which allows attackers to authenticate as a currently logged-in user and perform administrative tasks ...