Overview
Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800, versions 3.6.x to 3.8.3, contain multiple vulnerabilities.
Description
Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800, versions 3.6.x to 3.8.3, contain multiple vulnerabilities. CWE-352: Cross-Site Request Forgery (CSRF) - CVE-2015-2852 |
Impact
A remote, unauthenticated attacker may be able to obtain another user's session ID, spoof a victim user's session, and perform actions with the same permissions of a victim user. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 5.3 | E:POC/RL:OF/RC:C |
Environmental | 4.0 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
- https://bto.bluecoat.com/news/ssl-visibility-v3.8.4-released
- https://bto.bluecoat.com/security-advisory/sa96
- https://fishnetsecurity.com/6labs/blog/vulnerabilities-bluecoat-ssl-visibility-appliances
- http://cwe.mitre.org/data/definitions/352.html
- http://cwe.mitre.org/data/definitions/384.html
- http://cwe.mitre.org/data/definitions/20.html
- https://cwe.mitre.org/data/definitions/200.html
- https://cwe.mitre.org/data/definitions/79.html
Acknowledgements
Thanks to Tim MalcomVetter of FishNet Security for reporting this vulnerability.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2015-2852, CVE-2015-2853, CVE-2015-2854, CVE-2015-2855 |
Date Public: | 2015-05-29 |
Date First Published: | 2015-05-29 |
Date Last Updated: | 2015-06-02 15:14 UTC |
Document Revision: | 14 |