V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-2284
CVE
CriticalConfirmedExploit available

userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arb…

CVSS
10.0
Critical
EPSS
0.74
p99
Published
2015-01-01
Updated
2015-01-01
Description

userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling.

Tags · CWE
CWE-264
Affected products
Firewall_security_manager ≤ 6.6.5
CVSS vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.742 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
36679
exploitdb · https://www.exploit-db.com/exploits/36679
Enterprise
Affected products
ProductVendorStatus
firewall_security_manager*Tracked
Source databases
CVE
Related vulnerabilities