CVE-2015-0739
Summary
| CVE | CVE-2015-0739 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-05-19 02:00:18 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The Lights-Out Management (LOM) implementation in Cisco FireSIGHT System Software 5.3.0 on Sourcefire 3D Sensor devices allows remote authenticated users to perform arbitrary Baseboard Management Controller (BMC) file uploads via unspecified vectors, aka Bug ID CSCus87938. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Firesight System Software | 5.3.0 | All | All | All |
| Hardware | Cisco | Sourcefire 3d1000 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d2000 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d2100 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d2500 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d3500 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d4500 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d500 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d6500 Sensor | - | All | All | All |
| Hardware | Cisco | Sourcefire 3d9900 Sensor | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco FireSIGHT Sourcefire 3D System Input Validation Flaw Lets Remote Authenticated Users Upload Arbitrary Files - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco Sourcefire 3D System Lights-Out Management CVE-2015-0739 Arbitrary File Upload Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Sourcefire 3D System Lights-Out Management Arbitrary File Upload Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.