VulnerabilityModified
CVE-2015-5718
Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0 HF02 allows remote administrators to cause a denial of service (crash) via a crafted diagnostic command line request to…
MEDIUM 4.0EPSS 1.84%
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
Stack-based buffer overflow in the handle_debug_network function in the manager in Websense Content Gateway before 8.0.0 HF02 allows remote administrators to cause a denial of service (crash) via a crafted diagnostic command line request to submit_net_debug.cgi.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- websense/content gateway
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/132968/Websense-Triton-Content-Manager-8.0.0-Build-1165-Buffer-Overflow.htmlExploit
- http://seclists.org/fulldisclosure/2015/Aug/8Exploit
- http://www.securityfocus.com/archive/1/536138/100/0/threaded
- http://www.securitytracker.com/id/1033263
- http://www.websense.com/support/article/kbarticle/v8-0-0-About-Hotfix-02-for-Websense-Content-GatewayVendor Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150805-0_Websense_Content_Gateway_stack_buffer_overflow_in_handle_debug_network_v10.txtExploit
- http://packetstormsecurity.com/files/132968/Websense-Triton-Content-Manager-8.0.0-Build-1165-Buffer-Overflow.htmlExploit
- http://seclists.org/fulldisclosure/2015/Aug/8Exploit
- http://www.securityfocus.com/archive/1/536138/100/0/threaded
- http://www.securitytracker.com/id/1033263
- http://www.websense.com/support/article/kbarticle/v8-0-0-About-Hotfix-02-for-Websense-Content-GatewayVendor Advisory
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20150805-0_Websense_Content_Gateway_stack_buffer_overflow_in_handle_debug_network_v10.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.