CVE-2015-2853

Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web sessions by providing a session ID.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
blue_coatssl_visibility_appliance_sv3800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv2800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv1800_firmware
𝑥
≤ 3.8.3
blue_coatssl_visibility_appliance_sv800_firmware
𝑥
≤ 3.8.3
𝑥
= Vulnerable software versions