Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-2802


An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.


Published

2020-02-04T21:15:10.417

Last Modified

2024-11-21T02:28:06.247

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hp asset_manager 9.30 Yes
Application hp asset_manager 9.31 Yes
Application hp asset_manager 9.32 Yes
Application hp asset_manager 9.40 Yes
Application hp asset_manager 9.41 Yes
Application hp asset_manager 9.50 Yes
Application hp asset_manager_cloudsystem_chargeback 9.40 Yes
Application hp sitescope ≤ 11.24 Yes
Application hp sitescope 11.30 Yes
Operating System linux linux_kernel - No
Operating System microsoft windows - No
Operating System oracle solaris - No

References