CVE-2015-3140

HIGHCVSS 8.8/10EPSS 1.29%

Last modified

CVE-2015-3140 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567. EPSS estimates a 1.29% chance of exploitation in the next 30 days.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
1.29%

66.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
SynametricsSynaman1.0Build786
SynametricsSynaman1.1Build972
SynametricsSynaman2.0Build1185
SynametricsSynaman2.1Build1202
SynametricsSynaman2.2Build1205
SynametricsSynaman2.3Build1259
SynametricsSynaman2.4Build1272
SynametricsSynaman2.5Build1282
SynametricsSynaman2.6Build1328
SynametricsSynaman2.7Build1337
SynametricsSynaman3.0Build1358
SynametricsSynaman3.1Build1380
SynametricsSynaman3.2Build1393
SynametricsSynaman3.3Build1418
SynametricsSynaman3.4Build1434
SynametricsSyncrify1.3Build352
SynametricsSyncrify1.4Build379
SynametricsSyncrify2.0Build413
SynametricsSyncrify2.1Build420
SynametricsSyncrify2.2Build429
SynametricsSyncrify2.3Build443
SynametricsSyncrify2.4Build459
SynametricsSyncrify2.5Build473
SynametricsSyncrify2.6Build510
SynametricsSyncrify3.0Build580
SynametricsSyncrify3.1Build614
SynametricsSyncrify3.2Build629
SynametricsSyncrify3.3Build682
SynametricsSyncrify3.4Build725
SynametricsSyncrify3.5Build778
SynametricsSyncrify3.6Build800
SynametricsSyncrify3.7Build833
SynametricsSyntail1.0Build420
SynametricsSyntail1.1Build429
SynametricsSyntail1.2Build445
SynametricsSyntail1.5Build561

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-3140?
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567
How severe is CVE-2015-3140?
CVE-2015-3140 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 1.29% probability of exploitation in the next 30 days.
How do I fix CVE-2015-3140?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-3140?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST