VulnerabilityModified
CVE-2015-6843
Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to obtain access via a brute-force approach.
MEDIUM 5.0EPSS 2.94%
Does this matter?
Lower severity and a low EPSS score (2.94%). Track it; it rarely justifies an emergency change on its own.
Description
Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to obtain access via a brute-force approach.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.94% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- emc/sourceone email supervisor
- Source
- security_alert@emc.com
References
- http://packetstormsecurity.com/files/133922/EMC-SourceOne-Email-Supervisor-XSS-Session-Hijacking.htmlThird Party Advisory
- http://seclists.org/bugtraq/2015/Oct/58Mailing List
- http://www.securitytracker.com/id/1033787Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/133922/EMC-SourceOne-Email-Supervisor-XSS-Session-Hijacking.htmlThird Party Advisory
- http://seclists.org/bugtraq/2015/Oct/58Mailing List
- http://www.securitytracker.com/id/1033787Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.