ID

VAR-201504-0442


CVE

CVE-2015-3447


TITLE

Dell SonicWall SonicOS of macIpSpoofView.html Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2015-002514

DESCRIPTION

Multiple cross-site scripting (XSS) vulnerabilities in macIpSpoofView.html in Dell SonicWall SonicOS 7.5.0.12 and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) searchSpoof or (2) searchSpoofIpDet parameter. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. SonicOS 7.5.0.12 and 6.0 are vulnerable. Dell SonicWall SonicOS is a set of operating system specially designed for SonicWall firewall equipment of Dell (Dell). A cross-site scripting vulnerability exists in the macIpSpoofView.html file of Dell SonicWall SonicOS versions 7.5.0.12 and 6.x

Trust: 1.98

sources: NVD: CVE-2015-3447 // JVNDB: JVNDB-2015-002514 // BID: 74406 // VULHUB: VHN-81408

AFFECTED PRODUCTS

vendor:sonicwallmodel:sonicosscope:eqversion:7.5.0.12

Trust: 1.6

vendor:dellmodel:sonicwall sonicosscope:eqversion:7.5.0.12

Trust: 1.1

vendor:sonicwallmodel:sonicosscope:gteversion:6.0.0.0

Trust: 1.0

vendor:sonicwallmodel:sonicosscope:lteversion:6.2.2.0

Trust: 1.0

vendor:dellmodel:sonicwall sonicosscope:eqversion:6.x

Trust: 0.8

vendor:sonicwallmodel:sonicosscope:eqversion:6.2.2.0

Trust: 0.6

vendor:dellmodel:sonicwall sonicosscope:eqversion:6.0

Trust: 0.3

sources: BID: 74406 // JVNDB: JVNDB-2015-002514 // CNNVD: CNNVD-201504-588 // NVD: CVE-2015-3447

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3447
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-3447
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201504-588
value: MEDIUM

Trust: 0.6

VULHUB: VHN-81408
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-3447
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-81408
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-81408 // JVNDB: JVNDB-2015-002514 // CNNVD: CNNVD-201504-588 // NVD: CVE-2015-3447

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-81408 // JVNDB: JVNDB-2015-002514 // NVD: CVE-2015-3447

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201504-588

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201504-588

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002514

PATCH

title:Top Pageurl:http://www.sonicwall.com/japan/

Trust: 0.8

sources: JVNDB: JVNDB-2015-002514

EXTERNAL IDS

db:NVDid:CVE-2015-3447

Trust: 2.8

db:BIDid:74406

Trust: 1.4

db:SECTRACKid:1032204

Trust: 1.1

db:JVNDBid:JVNDB-2015-002514

Trust: 0.8

db:CNNVDid:CNNVD-201504-588

Trust: 0.7

db:VULHUBid:VHN-81408

Trust: 0.1

sources: VULHUB: VHN-81408 // BID: 74406 // JVNDB: JVNDB-2015-002514 // CNNVD: CNNVD-201504-588 // NVD: CVE-2015-3447

REFERENCES

url:http://www.vulnerability-lab.com/get_content.php?id=1359

Trust: 2.5

url:http://seclists.org/fulldisclosure/2015/apr/97

Trust: 1.7

url:http://www.securityfocus.com/bid/74406

Trust: 1.1

url:http://www.securityfocus.com/archive/1/535393/100/0/threaded

Trust: 1.1

url:http://www.securitytracker.com/id/1032204

Trust: 1.1

url:http://www.securityfocus.com/archive/1/archive/1/535393/100/0/threaded

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3447

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3447

Trust: 0.8

url:http://o-www.sonicwall.com/us/en/products/network_security_platform.html

Trust: 0.3

sources: VULHUB: VHN-81408 // BID: 74406 // JVNDB: JVNDB-2015-002514 // CNNVD: CNNVD-201504-588 // NVD: CVE-2015-3447

CREDITS

Vulnerability Laboratory

Trust: 0.3

sources: BID: 74406

SOURCES

db:VULHUBid:VHN-81408
db:BIDid:74406
db:JVNDBid:JVNDB-2015-002514
db:CNNVDid:CNNVD-201504-588
db:NVDid:CVE-2015-3447

LAST UPDATE DATE

2024-08-14T13:47:43.303000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-81408date:2018-10-09T00:00:00
db:BIDid:74406date:2015-04-23T00:00:00
db:JVNDBid:JVNDB-2015-002514date:2015-05-01T00:00:00
db:CNNVDid:CNNVD-201504-588date:2015-04-30T00:00:00
db:NVDid:CVE-2015-3447date:2018-10-09T19:56:55.453

SOURCES RELEASE DATE

db:VULHUBid:VHN-81408date:2015-04-29T00:00:00
db:BIDid:74406date:2015-04-23T00:00:00
db:JVNDBid:JVNDB-2015-002514date:2015-05-01T00:00:00
db:CNNVDid:CNNVD-201504-588date:2015-04-30T00:00:00
db:NVDid:CVE-2015-3447date:2015-04-29T20:59:04.623