Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.

Project Subscriptions

Vendors Products
Alcatel-lucent Subscribe
Omniswitch 10k Subscribe
Omniswitch 6250 Subscribe
Omniswitch 6400 Subscribe
Omniswitch 6450 Subscribe
Omniswitch 6850e Subscribe
Omniswitch 6855 Subscribe
Omniswitch 6860 Subscribe
Omniswitch 6900 Subscribe
Omniswitch 9000e Subscribe
Omniswitch Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2015-2893 Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web interface in Alcatel-Lucent OmniSwitch 6450, 6250, 6850E, 9000E, 6400, 6855, 6900, 10K, and 6860 with firmware 6.4.5.R02, 6.4.6.R01, 6.6.4.R01, 6.6.5.R02, 7.3.2.R01, 7.3.3.R01, 7.3.4.R01, and 8.1.1.R01 allows remote attackers to hijack the authentication of administrators for requests that create users via a crafted request.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T05:24:38.893Z

Reserved: 2015-03-30T00:00:00

Link: CVE-2015-2805

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-06-16T16:59:01.113

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-2805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses