CVE-2015-2873
Summary
| CVE | CVE-2015-2873 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-23 15:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the configuration via a direct request to the (1) system log URL, (2) whitelist URL, or (3) blacklist URL. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trendmicro | Deep Discovery Inspector | 3.5 | All | All | All |
| Application | Trendmicro | Deep Discovery Inspector | 3.5 | All | All | ja |
| Application | Trendmicro | Deep Discovery Inspector | 3.5 | All | All | zh |
| Application | Trendmicro | Deep Discovery Inspector | 3.6 | All | All | All |
| Application | Trendmicro | Deep Discovery Inspector | 3.7 | All | All | All |
| Application | Trendmicro | Deep Discovery Inspector | 3.7 | All | All | ja |
| Application | Trendmicro | Deep Discovery Inspector | 3.7 | All | All | zh |
| Application | Trendmicro | Deep Discovery Inspector | 3.8 | All | All | All |
| Application | Trendmicro | Deep Discovery Inspector | 3.8 | All | All | ja |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cross-Site Scripting Vulnerability [CVE-2015-2872] | af854a3a-2127-422b-91ae-364da2661108 | esupport.trendmicro.com | Patch, Vendor Advisory |
| Trend Micro Deep Discovery Inspector CVE-2015-2873 Multiple Authentication Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Vulnerability Note VU#248692 - Trend Micro Deep Discovery threat appliance contains multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.