CVE-2015-2852

EUVD-2015-2940
Cross-site request forgery (CSRF) vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack the authentication of administrators.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
blue_coatssl_visibility_appliance_sv2800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv1800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv3800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv800_firmware
𝑥
≤ 3.8.3
𝑥
= Vulnerable software versions