CVE-2015-2120
Hewlett-Packard SiteScope Log Analyzer Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in HP SiteScope 11.1x before 11.13, 11.2x before 11.24.391, and 11.3x before 11.30.521 allows remote authenticated users to gain privileges via unknown vectors, aka ZDI-CAN-2567.
Vulnerabilidad no especificada en HP SiteScope 11.1x anterior a 11.13, 11.2x anterior a 11.24.391, y 11.3x anterior a 11.30.521 permite a usuarios remotos autenticados ganar privilegios a través de vectores desconocidos, también conocido como ZDI-CAN-2567.
This vulnerability allows remote attackers to read arbitrary files on vulnerable installations of Hewlett-Packard SiteScope. Authentication is required to exploit this vulnerability.
The specific flaw exists within the Log Analysis Tool. This tool does not validate or restrict the log path allowing users to read the users.config file. A remote attacker can leverage this vulnerability to escalate privileges from the user to administrator role.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-02-27 CVE Reserved
- 2015-05-25 CVE Published
- 2024-08-06 CVE Updated
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/74801 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-15-239 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04688784 | 2016-12-31 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Sitescope Search vendor "Hp" for product "Sitescope" | 11.13 Search vendor "Hp" for product "Sitescope" and version "11.13" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Sitescope Search vendor "Hp" for product "Sitescope" | 11.24.391 Search vendor "Hp" for product "Sitescope" and version "11.24.391" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Sitescope Search vendor "Hp" for product "Sitescope" | 11.30.521 Search vendor "Hp" for product "Sitescope" and version "11.30.521" | - |
Affected
|