Lucene search

K
cveMitreCVE-2015-1187
HistorySep 21, 2017 - 4:29 p.m.

CVE-2015-1187

2017-09-2116:29:00
CWE-287
mitre
web.nvd.nist.gov
842
In Wild
4
cve-2015-1187
ping tool
remote attackers
arbitrary code execution
d-link
trendnet
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.932

Percentile

99.1%

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

Affected configurations

Nvd
Node
dlinkdir-626l_firmwareMatch1.04b04
AND
dlinkdir-626lMatch-
Node
dlinkdir-636l_firmwareMatch1.04
AND
dlinkdir-636lMatch-
Node
dlinkdir-808l_firmwareMatch1.03b05
AND
dlinkdir-808lMatch-
Node
dlinkdir-810l_firmwareMatch1.01b04
AND
dlinkdir-810lMatch-
Node
dlinkdir-810l_firmwareMatch2.02b01
AND
dlinkdir-810lMatch-
Node
dlinkdir-820l_firmwareMatch1.02b10
AND
dlinkdir-820lMatch-
Node
dlinkdir-820l_firmwareMatch1.05b03
AND
dlinkdir-820lMatch-
Node
dlinkdir-820l_firmwareMatch2.01b02
AND
dlinkdir-820lMatch-
Node
dlinkdir-826l_firmwareMatch1.00b23
AND
dlinkdir-826lMatch-
Node
dlinkdir-830l_firmwareMatch1.00b07
AND
dlinkdir-830lMatch-
Node
dlinkdir-836l_firmwareMatch1.01b03
AND
dlinkdir-836lMatch-
Node
trendnettew-731br_firmwareMatch2.01b01
AND
trendnettew-731brMatch-
Node
dlinkdir-651_firmwareMatch1.10nab02
AND
dlinkdir-651Match-
Node
trendnettew-651br_firmwareMatch-
AND
trendnettew-651brMatch-
Node
trendnettew-652br_firmwareMatch-
AND
trendnettew-652brMatch-
Node
trendnettew-711br_firmwareMatch1.00b31
AND
trendnettew-711brMatch-
Node
trendnettew-810dr_firmwareMatch1.00b19
AND
trendnettew-810drMatch-
Node
trendnettew-813dru_firmwareMatch1.00b23
AND
trendnettew-813druMatch-
VendorProductVersionCPE
dlinkdir-626l_firmware1.04cpe:2.3:o:dlink:dir-626l_firmware:1.04:b04:*:*:*:*:*:*
dlinkdir-626l-cpe:2.3:h:dlink:dir-626l:-:*:*:*:*:*:*:*
dlinkdir-636l_firmware1.04cpe:2.3:o:dlink:dir-636l_firmware:1.04:*:*:*:*:*:*:*
dlinkdir-636l-cpe:2.3:h:dlink:dir-636l:-:*:*:*:*:*:*:*
dlinkdir-808l_firmware1.03cpe:2.3:o:dlink:dir-808l_firmware:1.03:b05:*:*:*:*:*:*
dlinkdir-808l-cpe:2.3:h:dlink:dir-808l:-:*:*:*:*:*:*:*
dlinkdir-810l_firmware1.01cpe:2.3:o:dlink:dir-810l_firmware:1.01:b04:*:*:*:*:*:*
dlinkdir-810l-cpe:2.3:h:dlink:dir-810l:-:*:*:*:*:*:*:*
dlinkdir-810l_firmware2.02cpe:2.3:o:dlink:dir-810l_firmware:2.02:b01:*:*:*:*:*:*
dlinkdir-820l_firmware1.02cpe:2.3:o:dlink:dir-820l_firmware:1.02:b10:*:*:*:*:*:*
Rows per page:
1-10 of 331

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.932

Percentile

99.1%