← Back

CVE-2015-2805

nvd nist
Published: Jun 16, 2015Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.

Affected (8)

Omniswitch Firmware
Configuration A
8 vulnerable · 9 platform
Vulnerable SoftwareAffected Versions
Alcatel Lucent
Up to 6.4.5.r02
Up to 6.4.6.r01
Up to 6.6.4.r01
Up to 6.6.5.r02
Up to 7.3.2.r01
Up to 7.3.3.r01
Up to 7.3.4.r01
Up to 8.1.1.r01
Running on/withPlatform Versions
Alcatel Lucent
Omniswitch 10k
All versions
Alcatel Lucent
Omniswitch 6250
All versions
Alcatel Lucent
Omniswitch 6400
All versions
Alcatel Lucent
Omniswitch 6450
All versions
Alcatel Lucent
Omniswitch 6850e
All versions
Alcatel Lucent
Omniswitch 6855
All versions
Alcatel Lucent
Omniswitch 6860
All versions
Alcatel Lucent
Omniswitch 6900
All versions
Alcatel Lucent
Omniswitch 9000e
All versions

Timeline

No history available yet.