René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

90 lines
2.7 KiB
JSON

{
"id": "CVE-2015-7361",
"sourceIdentifier": "cve@mitre.org",
"published": "2015-10-15T20:59:01.833",
"lastModified": "2016-12-03T03:12:51.817",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain shell access via unspecified vectors."
},
{
"lang": "es",
"value": "FortiOS 5.2.3, cuando se configura para usar High Availability (HA) y la interfaz de administraci\u00f3n dedicada est\u00e1 habilitada, no requiere autenticaci\u00f3n para el acceso a la shell ZebOS en la interfaz de gesti\u00f3n dedicada HA, lo que permite a atacantes remotos obtener acceso a la shell a trav\u00e9s de vectores no especificados."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 9.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.6,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fortinet:fortios:5.2.3:*:*:*:*:*:*:*",
"matchCriteriaId": "27B4C672-7ED5-4113-87AE-5774D1263C0B"
}
]
}
]
}
],
"references": [
{
"url": "http://fortiguard.com/advisory/zebos-routing-remote-shell-service-enabled",
"source": "cve@mitre.org"
},
{
"url": "http://www.fortiguard.com/advisory/zebos-routing-remote-shell-service-enabled",
"source": "cve@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securitytracker.com/id/1033093",
"source": "cve@mitre.org"
}
]
}