Lucene search

K
cveCertccCVE-2016-1543
HistoryJun 13, 2016 - 2:59 p.m.

CVE-2016-1543

2016-06-1314:59:01
CWE-284
certcc
web.nvd.nist.gov
48
cve-2016-1543
rpc api
rscd agent
bmc bladelogic
server automation
bsa
authorization bypass
user passwords
remote attack

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.339

Percentile

97.1%

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.

Affected configurations

Nvd
Node
bmcbladelogic_server_automation_consoleMatch8.2.02
OR
bmcbladelogic_server_automation_consoleMatch8.2.03
OR
bmcbladelogic_server_automation_consoleMatch8.2.04
OR
bmcbladelogic_server_automation_consoleMatch8.3.00
OR
bmcbladelogic_server_automation_consoleMatch8.3.01
OR
bmcbladelogic_server_automation_consoleMatch8.3.02
OR
bmcbladelogic_server_automation_consoleMatch8.3.03
OR
bmcbladelogic_server_automation_consoleMatch8.5.00
OR
bmcbladelogic_server_automation_consoleMatch8.5.01
OR
bmcbladelogic_server_automation_consoleMatch8.6.00
OR
bmcbladelogic_server_automation_consoleMatch8.7.00
VendorProductVersionCPE
bmcbladelogic_server_automation_console8.2.02cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.02:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.2.03cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.03:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.2.04cpe:2.3:a:bmc:bladelogic_server_automation_console:8.2.04:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.00:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.01cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.01:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.02cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.02:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.3.03cpe:2.3:a:bmc:bladelogic_server_automation_console:8.3.03:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.5.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.5.00:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.5.01cpe:2.3:a:bmc:bladelogic_server_automation_console:8.5.01:*:*:*:*:*:*:*
bmcbladelogic_server_automation_console8.6.00cpe:2.3:a:bmc:bladelogic_server_automation_console:8.6.00:*:*:*:*:*:*:*
Rows per page:
1-10 of 111

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.339

Percentile

97.1%