{"api_version":"1","generated_at":"2026-04-23T08:03:46+00:00","cve":"CVE-2015-0544","urls":{"html":"https://cve.report/CVE-2015-0544","api":"https://cve.report/api/cve/CVE-2015-0544.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-0544","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-0544"},"summary":{"title":"CVE-2015-0544","description":"EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.","state":"PUBLIC","assigner":"security_alert@emc.com","published_at":"2015-07-05 10:59:00","updated_at":"2016-12-28 02:59:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://seclists.org/bugtraq/2015/Jun/132","name":"20150626 ESA-2015-097: EMC Secure Remote Services (ESRS) Virtual Edition (VE) Multiple Security Vulnerabilities","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: ESA-2015-097: EMC Secure Remote Services (ESRS) Virtual Edition (VE) Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1032740","name":"1032740","refsource":"SECTRACK","tags":[],"title":"EMC Secure Remote Services Virtual Edition Certificate Validation and Session Cookie Randomization Flaws Let Remote Users Spoof Systems and Gain Full Control of the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-0544","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0544","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"544","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"secure_remote_services","cpe6":"3.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"virtual","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"544","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"secure_remote_services","cpe6":"3.03","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"virtual","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"544","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"secure_remote_services","cpe6":"3.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"virtual","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"544","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"secure_remote_services","cpe6":"3.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"virtual","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"544","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"secure_remote_services","cpe6":"3.03","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"virtual","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"544","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"secure_remote_services","cpe6":"3.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"virtual","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2015-0544","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1032740","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1032740"},{"name":"20150626 ESA-2015-097: EMC Secure Remote Services (ESRS) Virtual Edition (VE) Multiple Security Vulnerabilities","refsource":"BUGTRAQ","url":"http://seclists.org/bugtraq/2015/Jun/132"}]}},"nvd":{"publishedDate":"2015-07-05 10:59:00","lastModifiedDate":"2016-12-28 02:59:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:emc:secure_remote_services:3.04:*:*:*:virtual:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:emc:secure_remote_services:3.03:*:*:*:virtual:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:emc:secure_remote_services:3.02:*:*:*:virtual:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"544","Ordinal":"77005","Title":"CVE-2015-0544","CVE":"CVE-2015-0544","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"544","Ordinal":"1","NoteData":"EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"544","Ordinal":"2","NoteData":"2015-07-05","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"544","Ordinal":"3","NoteData":"2016-12-23","Type":"Other","Title":"Modified"}]}}}