VulnerabilityModified
CVE-2016-7815
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.
MEDIUM 4.2EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.
- CVSS 3.0
- 4.2 MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- cybozu/remote service manager
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN19241292/index.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95379Third Party Advisory, VDB Entry
- https://support.cybozu.com/ja-jp/article/9689Vendor Advisory
- http://jvn.jp/en/jp/JVN19241292/index.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95379Third Party Advisory, VDB Entry
- https://support.cybozu.com/ja-jp/article/9689Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.