CVE-2015-1454
Last modified
CVE-2015-1454 is a vulnerability of currently unknown severity. Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate.. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bluecoat | Proxyclient | >= 3.3, < 3.3.3.3 |
| Bluecoat | Proxyclient | >= 3.4, < 3.4.4.10 |
| Bluecoat | Unified Agent | <= 4.1.3 |
References
- http://secunia.com/advisories/62617Third Party Advisory
- https://bto.bluecoat.com/security-advisory/sa89Vendor Advisory
- http://secunia.com/advisories/62617Third Party Advisory
- https://bto.bluecoat.com/security-advisory/sa89Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1454?
How severe is CVE-2015-1454?
How do I fix CVE-2015-1454?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-1448The integrated management service on Siemens Ruggedcom WIN51…
- CVE-2015-1449Buffer overflow in the integrated web server on Siemens Rugg…
- CVE-2015-1450SQL injection vulnerability in Restaurant Biller allows remo…
- CVE-2015-1451Multiple cross-site scripting (XSS) vulnerabilities in Forti…
- CVE-2015-1452The Control and Provisioning of Wireless Access Points (CAPW…
- CVE-2015-1453The qm class in Fortinet FortiClient 5.2.3.091 for Android u…
- CVE-2015-1455Fortinet FortiAuthenticator 3.0.0 has a password of (1) slon…
- CVE-2015-1456Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL userna…
- CVE-2015-1457Fortinet FortiAuthenticator 3.0.0 allows local users to read…
- CVE-2015-1458Fortinet FortiAuthenticator 3.0.0 allows local users to bypa…
- CVE-2015-1459Cross-site scripting (XSS) vulnerability in Fortinet FortiAu…
- CVE-2015-1460Huawei Quidway switches with firmware before V200R005C00SPC3…
Are you affected by CVE-2015-1454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
