CVE-2015-1454
Published Feb 2, 2015
Last updated 6 years ago
Overview
- Description
- Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.1
- Impact score
- 6.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:C/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:bluecoat:proxyclient:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "960A430A-202B-46CC-BA1B-F2C6355072F9", "versionEndExcluding": "3.3.3.3", "versionStartIncluding": "3.3" }, { "criteria": "cpe:2.3:a:bluecoat:proxyclient:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1696A8C6-E850-403F-884C-790A9BE10E9F", "versionEndExcluding": "3.4.4.10", "versionStartIncluding": "3.4" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:bluecoat:unified_agent:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8938BC12-B151-49BE-B956-82FAE894A31F", "versionEndIncluding": "4.1.3" } ], "operator": "OR" } ] } ]