Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-6860


HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-6859.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.4, requiring local system access to exploit with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 54 products from hp, from hp, from hp and 51 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2016, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2016-01-05T11:59:06.520

Last Modified

2026-06-17T00:31:32.757

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.4 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hp network_switch_software ≤ 15.18.0 Yes
Hardware hp j8692a * Yes
Hardware hp j8693a * Yes
Hardware hp j8697a * Yes
Hardware hp j8698a * Yes
Hardware hp j8699a * Yes
Hardware hp j8700a * Yes
Hardware hp j8715a * Yes
Hardware hp j8715b * Yes
Hardware hp j8992a * Yes
Hardware hp j9091a * Yes
Hardware hp j9263a * Yes
Hardware hp j9264a * Yes
Hardware hp j9265a * Yes
Hardware hp j9310a * Yes
Hardware hp j9311a * Yes
Hardware hp j9447a * Yes
Hardware hp j9448a * Yes
Hardware hp j9451a * Yes
Hardware hp j9452a * Yes
Hardware hp j9470a * Yes
Hardware hp j9471a * Yes
Hardware hp j9472a * Yes
Hardware hp j9473a * Yes
Hardware hp j9475a * Yes
Hardware hp j9532a * Yes
Hardware hp j9533a * Yes
Hardware hp j9539a * Yes
Hardware hp j9540a * Yes
Hardware hp j9573a * Yes
Hardware hp j9574a * Yes
Hardware hp j9575a * Yes
Hardware hp j9576a * Yes
Hardware hp j9584a * Yes
Hardware hp j9585a * Yes
Hardware hp j9586a * Yes
Hardware hp j9587a * Yes
Hardware hp j9588a * Yes
Hardware hp j9638a * Yes
Hardware hp j9639a * Yes
Hardware hp j9640a * Yes
Hardware hp j9641a * Yes
Hardware hp j9642a * Yes
Hardware hp j9643a * Yes
Hardware hp j9821a * Yes
Hardware hp j9822a * Yes
Hardware hp j9823a * Yes
Hardware hp j9824a * Yes
Hardware hp j9825a * Yes
Hardware hp j9826a * Yes
Hardware hp j9850a * Yes
Hardware hp j9851a * Yes
Hardware hp j9866a * Yes
Hardware hp j9868a * Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For hp's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.