CVE-2016-1542

Scores

EPSS

0.713medium71.3%
0%20%40%60%80%100%

Percentile: 71.3%

CVSS

7.5high3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Description

The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-20

Exploits

Exploit ID: 43902

Source: exploitdb

URL: https://www.exploit-db.com/exploits/43902

Exploit ID: 43939

Source: exploitdb

URL: https://www.exploit-db.com/exploits/43939

Exploit ID: CVE-2016-1542

Source: github-poc

URL: https://github.com/patriknordlen/bladelogic_bmc-cve-2016-1542

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: bladelogic_server_automation_console

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.02:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:bmc:bladelogic_...

Source: nvd

End of list