Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-0739


The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug ID CSCus87938.


Published

2015-05-19T02:00:18.917

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco firesight_system_software 5.3.0 Yes
Hardware cisco sourcefire_3d1000_sensor - No
Hardware cisco sourcefire_3d2000_sensor - No
Hardware cisco sourcefire_3d2100_sensor - No
Hardware cisco sourcefire_3d2500_sensor - No
Hardware cisco sourcefire_3d3500_sensor - No
Hardware cisco sourcefire_3d4500_sensor - No
Hardware cisco sourcefire_3d500_sensor - No
Hardware cisco sourcefire_3d6500_sensor - No
Hardware cisco sourcefire_3d9900_sensor - No

References