6.8
CVSSv2

CVE-2015-2805

Published: 16/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote malicious users to hijack the authentication of administrators for requests that create users via a crafted request.

Vulnerable Product Search on Vulmon Subscribe to Product

alcatel-lucent omniswitch_firmware

Exploits

Advisory: Alcatel-Lucent OmniSwitch Web Interface Cross-Site Request Forgery During a penetration test, RedTeam Pentesting discovered a vulnerability in the management web interface of an Alcatel-Lucent OmniSwitch 6450 The management web interface has no protection against cross-site request forgery attacks This allows specially crafted web page ...
During a penetration test, RedTeam Pentesting discovered a vulnerability in the management web interface of an Alcatel-Lucent OmniSwitch 6450 The management web interface has no protection against cross-site request forgery attacks This allows specially crafted web pages to change the switch configuration and create users, if an administrator acc ...