SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-3373

The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.

MEDIUM 5.0EPSS 2.07%

Does this matter?

Lower severity and a low EPSS score (2.07%). Track it; it rarely justifies an emergency change on its own.

Description

The Amazon AWS module before 7.x-1.3 for Drupal uses the base URL and AWS access key to generate the access token, which makes it easier for remote attackers to guess the token value and create backups via a crafted URL.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.07% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
amazon aws project/amazon aws
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.