CVE-2015-2804

The management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, and 6855 with firmware before 6.6.4.309.R01 and 6.6.5.x before 6.6.5.80.R02 generates weak session identifiers, which allows remote attackers to hijack arbitrary sessions via a brute force attack.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:alcatel-lucent:omniswitch_6250:*:*:*:*:*:*:*:*
cpe:2.3:h:alcatel-lucent:omniswitch_6400:*:*:*:*:*:*:*:*
cpe:2.3:h:alcatel-lucent:omniswitch_6450:*:*:*:*:*:*:*:*
cpe:2.3:h:alcatel-lucent:omniswitch_6850e:*:*:*:*:*:*:*:*
cpe:2.3:h:alcatel-lucent:omniswitch_6855:*:*:*:*:*:*:*:*
cpe:2.3:h:alcatel-lucent:omniswitch_9000e:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-06-16 16:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-2804

Mitre link : CVE-2015-2804

CVE.ORG link : CVE-2015-2804


JSON object : View

Products Affected

alcatel-lucent

  • omniswitch_9000e
  • omniswitch_6450
  • omniswitch_6400
  • omniswitch_6855
  • omniswitch_6250
  • omniswitch_firmware
  • omniswitch_6850e
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor