CVE-2015-2284 is a critical vulnerability affecting SolarWinds Firewall Security Manager (FSM) versions prior to 6.6.5 HotFix1, specifically stemming from improper client session handling within the userlogin.jsp component. This flaw carries a maximum CVSS score of 10.0, allowing unauthenticated remote attackers to execute arbitrary code and gain elevated privileges through low-complexity vectors. Although there is no current evidence of active exploitation in the wild or a listing in the CISA KEV, the presence of a Metasploit module and a high EPSS score of 0.76 indicate a significant risk of weaponization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.6.5CPE matchmatch criteria | cpe:2.3:a:solarwinds:firewall_security_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.