Lucene search

K
cveMitreCVE-2015-2828
HistoryApr 08, 2015 - 1:59 a.m.

CVE-2015-2828

2015-04-0801:59:04
CWE-264
mitre
web.nvd.nist.gov
26
cve-2015-2828
ca spectrum
nvd
information security
remote code execution
java serialization

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

68.0%

CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain administrative privileges via crafted object data.

Affected configurations

Nvd
Node
broadcomspectrumMatch9.2
OR
broadcomspectrumMatch9.3
VendorProductVersionCPE
broadcomspectrum9.2cpe:2.3:a:broadcom:spectrum:9.2:*:*:*:*:*:*:*
broadcomspectrum9.3cpe:2.3:a:broadcom:spectrum:9.3:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

68.0%