CVE-2015-2852
Published May 30, 2015
Last updated 8 years ago
Overview
- Description
- Cross-site request forgery (CSRF) vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack the authentication of administrators.
- Source
- cret@cert.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv2800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "041A6762-C233-4163-8692-4DE054F1C9EE", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv2800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A6B04FC6-F165-4590-B088-7F126667ACD3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv1800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "658F9B38-DA76-4CF8-961C-DCD596DEC697", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv1800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F280A1EE-FEB6-435E-B566-132E9C2F54C2" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv3800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33E52942-0C82-472D-8065-8D33221285EE", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv3800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E7CA4AEA-C309-4E96-8835-CADB7FA32C05" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:blue_coat:ssl_visibility_appliance_sv800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A543761-A119-465D-A249-47347CE5EED9", "versionEndIncluding": "3.8.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:blue_coat:ssl_visibility_appliance_sv800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EB72CFF6-C8B6-429C-A036-2560CAE3C713" } ], "operator": "OR" } ], "operator": "AND" } ]