CVE-2015-4586: CSRF
Published Jun 23, 2015
·Updated
Cross-site request forgery (CSRF) vulnerability in Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL with firmware 1.0.0.20h.HOL allows remote attackers to hijack the authentication of administrators for requests that create a user account via an adduser action in a request to password.cmd.
Affected Software
2 affected components
Alcatel-Lucent Cellpipe 7130 Rg 5ae.m2013 Hol Firmware=1.0.0.20h.hol
Alcatel-Lucent CellPipe 7130 RG 5Ae.M2013 HOL
Event History
Jun 23, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4586?
CVE-2015-4586 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-4586?
To mitigate CVE-2015-4586, update the Alcatel-Lucent CellPipe 7130 RG firmware to the latest version.
3
What type of vulnerability is CVE-2015-4586?
CVE-2015-4586 is a cross-site request forgery (CSRF) vulnerability.
4
Who is affected by CVE-2015-4586?
Administrators of Alcatel-Lucent CellPipe 7130 RG devices running firmware 1.0.0.20h.HOL are affected by CVE-2015-4586.
5
What can attackers do with CVE-2015-4586?
Attackers can hijack administrator authentication to create user accounts due to CVE-2015-4586.