CVE-2016-15046 describes a client-side remote code execution vulnerability in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4. This flaw leverages improper restrictions on the Apache ActiveMQ PUT method, combined with a Cross-Origin Resource Sharing (CORS) bypass and JavaScript-triggered file uploads. An attacker can exploit this to achieve arbitrary code execution with SYSTEM privileges on affected systems. The vulnerability has a high severity CVSS score of 8.6, indicating a network-based attack with low complexity and requiring user interaction, leading to high impact on confidentiality, integrity, and availability. It bypasses previous server-side mitigations by shifting the attack to the client-side. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Hanwha | Smart Security Manager (SSM) | 1.32, 1.4CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.