CVE-2015-0739

The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug ID CSCus87938.
References
Link Resource
http://tools.cisco.com/security/center/viewAlert.x?alertId=38905 Vendor Advisory
http://www.securitytracker.com/id/1032359 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/74709 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:cisco:firesight_system_software:5.3.0:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:sourcefire_3d2500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d3500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d4500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d6500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d1000_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d2100_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d9900_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d2000_sensor:-:*:*:*:*:*:*:*

Information

Published : 2015-05-18 19:00

Updated : 2017-01-06 09:09


NVD link : CVE-2015-0739

Mitre link : CVE-2015-0739


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

cisco

  • sourcefire_3d3500_sensor
  • sourcefire_3d500_sensor
  • sourcefire_3d2100_sensor
  • sourcefire_3d9900_sensor
  • sourcefire_3d6500_sensor
  • sourcefire_3d2000_sensor
  • firesight_system_software
  • sourcefire_3d2500_sensor
  • sourcefire_3d4500_sensor
  • sourcefire_3d1000_sensor