{"api_version":"1","generated_at":"2026-07-23T09:33:47+00:00","cve":"CVE-2015-7287","urls":{"html":"https://cve.report/CVE-2015-7287","api":"https://cve.report/api/cve/CVE-2015-7287.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-7287","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-7287"},"summary":{"title":"CVE-2015-7287","description":"CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS message.","state":"PUBLISHED","assigner":"certcc","published_at":"2015-11-25 04:59:04","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/428280","name":"http://www.kb.cert.org/vuls/id/428280","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#428280 - CSL DualCom GPRS CS2300-R alarm signalling boards contain multiple vulnerabilties","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/BLUU-A3NQAL","name":"http://www.kb.cert.org/vuls/id/BLUU-A3NQAL","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"VU#428280 - CSL DualCom GPRS CS2300-R alarm signalling boards contain multiple vulnerabilties","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://cybergibbons.com/?p=2844","name":"http://cybergibbons.com/?p=2844","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"» CSL Dualcom CS2300-R signalling unit vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-7287","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7287","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"7287","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"csl_dualcom","cpe5":"gprs","cpe6":"cs2300-r","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7287","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"csl_dualcom","cpe5":"gprs_cs2300-r_firmware","cpe6":"1.25","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"7287","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"csl_dualcom","cpe5":"gprs_cs2300-r_firmware","cpe6":"3.53","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T07:43:46.131Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#428280","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/428280"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://cybergibbons.com/?p=2844"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/BLUU-A3NQAL"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-11-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-11-25T04:57:04.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#428280","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/428280"},{"tags":["x_refsource_MISC"],"url":"http://cybergibbons.com/?p=2844"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kb.cert.org/vuls/id/BLUU-A3NQAL"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2015-7287","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#428280","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/428280"},{"name":"http://cybergibbons.com/?p=2844","refsource":"MISC","url":"http://cybergibbons.com/?p=2844"},{"name":"http://www.kb.cert.org/vuls/id/BLUU-A3NQAL","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/BLUU-A3NQAL"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2015-7287","datePublished":"2015-11-25T02:00:00.000Z","dateReserved":"2015-09-18T00:00:00.000Z","dateUpdated":"2024-08-06T07:43:46.131Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-11-25 04:59:04","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:csl_dualcom:gprs_cs2300-r_firmware:1.25:*:*:*:*:*:*:*","matchCriteriaId":"2397CE4A-E81A-4AC3-B270-55B9C3B048EA"},{"vulnerable":true,"criteria":"cpe:2.3:o:csl_dualcom:gprs_cs2300-r_firmware:3.53:*:*:*:*:*:*:*","matchCriteriaId":"81B16396-C7FC-41B5-B7F4-FEA34DC2D0A9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:csl_dualcom:gprs:cs2300-r:*:*:*:*:*:*:*","matchCriteriaId":"31C0CB19-FCF0-42D7-B206-B0DB2D92E3A2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"7287","Ordinal":"1","Title":"CVE-2015-7287","CVE":"CVE-2015-7287","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"7287","Ordinal":"1","NoteData":"CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS message.","Type":"Description","Title":"CVE-2015-7287"},{"CveYear":"2015","CveId":"7287","Ordinal":"2","NoteData":"2015-11-24","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"7287","Ordinal":"3","NoteData":"2015-11-24","Type":"Other","Title":"Modified"}]}}}