Lucene search

K
cveMitreCVE-2015-4460
HistoryJul 16, 2015 - 8:59 p.m.

CVE-2015-4460

2015-07-1620:59:00
CWE-352
mitre
web.nvd.nist.gov
38
cve-2015-4460
cross-site request forgery
csrf vulnerability
b.a.s c2box
security vulnerability
nvd
authentication hijacking

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.007

Percentile

80.2%

Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box before 4.0.0 (r19171) allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via certain vectors.

Affected configurations

Nvd
Node
boxautomationc2boxRange4.0.0
VendorProductVersionCPE
boxautomationc2box*cpe:2.3:a:boxautomation:c2box:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.007

Percentile

80.2%