CVE-2015-2805: CSRF
Cross-site request forgery (CSRF) vulnerability in sec/content/secasauserslocaldbadd.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2805?
The severity of CVE-2015-2805 is categorized as Medium, indicating a moderate risk to affected systems.
How do I fix CVE-2015-2805?
To fix CVE-2015-2805, update the affected Alcatel-Lucent OmniSwitch firmware to a version later than 8.1.1.R01.
What systems are affected by CVE-2015-2805?
CVE-2015-2805 affects Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 running specific firmware versions.
What type of vulnerability is CVE-2015-2805?
CVE-2015-2805 is a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2015-2805 be exploited remotely?
Yes, CVE-2015-2805 can be exploited remotely without authentication, which makes it a significant security concern.