VulnerabilityModified
CVE-2015-6029
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
MEDIUM 5.0EPSS 4.44%
Does this matter?
Lower severity and a low EPSS score (4.44%). Track it; it rarely justifies an emergency change on its own.
Description
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 4.44% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- hp/arcsight logger
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/77128
- https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04863612Vendor Advisory
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/77128
- https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04863612Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.