ID

VAR-201804-0265


CVE

CVE-2015-0151


TITLE

D-Link DIR-815 Cross-Site Request Forgery Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2018-15271 // CNNVD: CNNVD-201804-588

DESCRIPTION

Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. D-Link DIR-815 Contains a cross-site request forgery vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-815 is a wireless router product from D-Link. A remote attacker could exploit the vulnerability to spoof a malicious website to implement a cross-site scripting attack, causing the web cache to poison or perform other malicious operations

Trust: 2.16

sources: NVD: CVE-2015-0151 // JVNDB: JVNDB-2015-008180 // CNVD: CNVD-2018-15271

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-15271

AFFECTED PRODUCTS

vendor:dlinkmodel:dir-815scope:ltversion:2.07.b01

Trust: 1.0

vendor:d linkmodel:dir-815scope:ltversion:2.07.b01

Trust: 0.8

vendor:d linkmodel:dir-815 <2.07.b01scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-15271 // JVNDB: JVNDB-2015-008180 // NVD: CVE-2015-0151

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0151
value: HIGH

Trust: 1.0

NVD: CVE-2015-0151
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-15271
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201804-588
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2015-0151
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: CVE-2015-0151
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2018-15271
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2015-0151
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.0

NVD: CVE-2015-0151
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2018-15271 // JVNDB: JVNDB-2015-008180 // CNNVD: CNNVD-201804-588 // NVD: CVE-2015-0151

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.8

sources: JVNDB: JVNDB-2015-008180 // NVD: CVE-2015-0151

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201804-588

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201804-588

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-008180

PATCH

title:DIR-815 Firmware Patch Notesurl:ftp://ftp2.dlink.com/SECURITY_ADVISEMENTS/DIR-815/REVB/DIR-815_REVB_FIRMWARE_PATCH_NOTES_2.07.B01_EN.PDF

Trust: 0.8

title:Patch for D-LinkDIR-815 Cross-Site Request Forgery Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/137331

Trust: 0.6

title:D-Link DIR-815 Fixes for cross-site request forgery vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=83337

Trust: 0.6

sources: CNVD: CNVD-2018-15271 // JVNDB: JVNDB-2015-008180 // CNNVD: CNNVD-201804-588

EXTERNAL IDS

db:NVDid:CVE-2015-0151

Trust: 3.0

db:JVNDBid:JVNDB-2015-008180

Trust: 0.8

db:CNVDid:CNVD-2018-15271

Trust: 0.6

db:CNNVDid:CNNVD-201804-588

Trust: 0.6

sources: CNVD: CNVD-2018-15271 // JVNDB: JVNDB-2015-008180 // CNNVD: CNNVD-201804-588 // NVD: CVE-2015-0151

REFERENCES

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/110584

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2015-0151

Trust: 1.4

url:ftp://ftp2.dlink.com/security_advisements/dir-815/revb/dir-815_revb_firmware_patch_notes_2.07.b01_en.pdf

Trust: 1.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0151

Trust: 0.8

sources: CNVD: CNVD-2018-15271 // JVNDB: JVNDB-2015-008180 // CNNVD: CNNVD-201804-588 // NVD: CVE-2015-0151

SOURCES

db:CNVDid:CNVD-2018-15271
db:JVNDBid:JVNDB-2015-008180
db:CNNVDid:CNNVD-201804-588
db:NVDid:CVE-2015-0151

LAST UPDATE DATE

2024-11-23T22:48:44.815000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-15271date:2018-08-15T00:00:00
db:JVNDBid:JVNDB-2015-008180date:2018-06-08T00:00:00
db:CNNVDid:CNNVD-201804-588date:2023-04-27T00:00:00
db:NVDid:CVE-2015-0151date:2024-11-21T02:22:27.530

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-15271date:2018-08-14T00:00:00
db:JVNDBid:JVNDB-2015-008180date:2018-06-08T00:00:00
db:CNNVDid:CNNVD-201804-588date:2018-04-12T00:00:00
db:NVDid:CVE-2015-0151date:2018-04-12T21:29:00.723