Lucene search

K
cve[email protected]CVE-2015-2802
HistoryFeb 04, 2020 - 9:15 p.m.

CVE-2015-2802

2020-02-0421:15:10
CWE-200
web.nvd.nist.gov
45
cve-2015-2802
information disclosure
hp
sitescope
asset manager
windows
linux
solaris
tls vulnerability
rc4 cipher bar mitzvah vulnerability
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.8%

An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Manager 9.30 through 9.32, 9.40 through 9.41, 9.50, and Asset Manager Cloudsystem Chargeback 9.40, which could let a remote malicious user obtain sensitive information. This is the TLS vulnerability known as the RC4 cipher Bar Mitzvah vulnerability.

Affected configurations

NVD
Node
hpasset_managerMatch9.30
OR
hpasset_managerMatch9.31
OR
hpasset_managerMatch9.32
OR
hpasset_managerMatch9.40
OR
hpasset_managerMatch9.41
OR
hpasset_managerMatch9.50
OR
hpasset_manager_cloudsystem_chargebackMatch9.40
Node
linuxlinux_kernelMatch-
OR
microsoftwindowsMatch-
OR
oraclesolarisMatch-
AND
hpsitescopeRange11.2011.24
OR
hpsitescopeMatch11.30

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

79.8%

Related for CVE-2015-2802