CVE-2015-7287
Summary
| CVE | CVE-2015-7287 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-25 04:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS message. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Csl Dualcom | Gprs | cs2300-r | All | All | All |
| Operating System | Csl Dualcom | Gprs Cs2300-r Firmware | 1.25 | All | All | All |
| Operating System | Csl Dualcom | Gprs Cs2300-r Firmware | 3.53 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Note VU#428280 - CSL DualCom GPRS CS2300-R alarm signalling boards contain multiple vulnerabilties | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| VU#428280 - CSL DualCom GPRS CS2300-R alarm signalling boards contain multiple vulnerabilties | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| » CSL Dualcom CS2300-R signalling unit vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | cybergibbons.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.