CVE-2015-6021 describes a Cross-Site Scripting (XSS) vulnerability in Spiceworks Desktop versions prior to 2015-12-01, specifically exploitable through a crafted SNMP response. This medium-severity vulnerability (CVSS 6.1) requires user interaction and network access, potentially leading to limited impact on confidentiality and integrity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.5.00093CPE matchmatch criteria | cpe:2.3:a:spiceworks:desktop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.