First published: Tue May 19 2015(Updated: )
The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug ID CSCus87938.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco FireSIGHT System Software | =5.3.0 | |
Cisco Sourcefire 3d1000 Sensor | ||
Cisco Sourcefire 3d2000 Sensor | ||
Cisco Sourcefire 3d2100 Sensor | ||
Cisco Sourcefire 3d2500 Sensor | ||
Cisco Sourcefire 3d3500 Sensor | ||
Cisco Sourcefire 3d4500 Sensor | ||
Cisco Sourcefire 3d500 Sensor | ||
Cisco Sourcefire 3d6500 Sensor | ||
Cisco Sourcefire 3d9900 Sensor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0739 has a medium severity rating as it allows remote authenticated users to upload arbitrary files.
To address CVE-2015-0739, it is recommended to upgrade to a fixed version of Cisco FireSIGHT System Software.
CVE-2015-0739 affects remote authenticated users of Cisco FireSIGHT System Software 5.3.0.
CVE-2015-0739 allows an attacker to perform arbitrary Baseboard Management Controller file uploads.
No, CVE-2015-0739 is specific to Cisco FireSIGHT System Software 5.3.0 and does not affect other Sourcefire sensor models.