CVE-2015-0739

The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug ID CSCus87938.
References
Link Resource
http://tools.cisco.com/security/center/viewAlert.x?alertId=38905 Vendor Advisory
http://www.securityfocus.com/bid/74709 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1032359 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:cisco:firesight_system_software:5.3.0:*:*:*:*:*:*:*
OR cpe:2.3:h:cisco:sourcefire_3d1000_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d2000_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d2100_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d2500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d3500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d4500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d6500_sensor:-:*:*:*:*:*:*:*
cpe:2.3:h:cisco:sourcefire_3d9900_sensor:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-05-19 02:00

Updated : 2023-12-10 11:46


NVD link : CVE-2015-0739

Mitre link : CVE-2015-0739

CVE.ORG link : CVE-2015-0739


JSON object : View

Products Affected

cisco

  • sourcefire_3d4500_sensor
  • sourcefire_3d1000_sensor
  • firesight_system_software
  • sourcefire_3d500_sensor
  • sourcefire_3d6500_sensor
  • sourcefire_3d2100_sensor
  • sourcefire_3d2000_sensor
  • sourcefire_3d2500_sensor
  • sourcefire_3d3500_sensor
  • sourcefire_3d9900_sensor
CWE
CWE-20

Improper Input Validation