CVE-2015-2805 describes a Cross-Site Request Forgery (CSRF) vulnerability in the management web interface of various Alcatel-Lucent OmniSwitch models running specific firmware versions. This flaw allows remote attackers to hijack an administrator's authenticated session to create new users via a specially crafted request. The vulnerability has a CVSS score of 6.8, indicating medium severity, and is rated as high risk by FAUCET (85/100). Its attack vector is network-based, with medium attack complexity, and successful exploitation can lead to unauthorized user creation, impacting confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an exploit for this vulnerability is publicly available on ExploitDB. Despite this, there is no evidence of active exploitation, and the CVE has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.4.5.r02CPE matchmatch criteria | cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:* | ||
<= 6.4.6.r01CPE matchmatch criteria | cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:* | ||
<= 6.6.4.r01CPE matchmatch criteria | cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:* | ||
<= 6.6.5.r02CPE matchmatch criteria | cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:* | ||
<= 7.3.2.r01CPE matchmatch criteria | cpe:2.3:o:alcatel-lucent:omniswitch_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.