First published: Wed Nov 04 2015(Updated: )
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP ArcSight Connectors | <=7.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2902 is classified as a moderate severity vulnerability.
To fix CVE-2015-2902, upgrade HP ArcSight SmartConnectors to version 7.1.6 or later.
HP ArcSight SmartConnectors versions prior to 7.1.6 are affected by CVE-2015-2902.
CVE-2015-2902 enables man-in-the-middle attacks due to lack of X.509 certificate verification.
Attackers can obtain sensitive information by spoofing Logger devices through CVE-2015-2902.