← All CVEs

CVE-2015-5082

high · 10

Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.

10
CVSS
69.9%
EPSS (exploit prob.)
99th
EPSS percentile
2015-09-28
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
endian_firewallendian_firewall<= 2.5.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-5082