CVE-2015-6029
UnknownEPSS 4.44%
Last modified
CVE-2015-6029 is a vulnerability of currently unknown severity. HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.. EPSS estimates a 4.44% chance of exploitation in the next 30 days.
Description
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Arcsight Logger | 6.0.0.7307.1 |
References
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6029?
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
How severe is CVE-2015-6029?
Severity scoring for CVE-2015-6029 is pending analysis. The EPSS model estimates a 4.44% probability of exploitation in the next 30 days.
How do I fix CVE-2015-6029?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-6021Spiceworks Desktop before 2015-12-01 has XSS via an SNMP res…
- CVE-2015-6022Unrestricted file upload vulnerability in QNAP Signage Stati…
- CVE-2015-6023ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers wi…
- CVE-2015-6024ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers wi…
- CVE-2015-6027Castle Rock Computing SNMPc before 2015-12-17 has XSS via SN…6.1
- CVE-2015-6028Castle Rock Computing SNMPc before 2015-12-17 has SQL inject…8.8
- CVE-2015-6030HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8…
- CVE-2015-6031Buffer overflow in the IGDstartelt function in igd_desc_pars…
- CVE-2015-6032Qolsys IQ Panel (aka QOL) before 1.5.1 has hardcoded cryptog…
- CVE-2015-6033Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the d…
- CVE-2015-6034EPSON Network Utility 4.10 uses weak permissions (Everyone: …
- CVE-2015-6035Opsview before 2015-11-06 has XSS via SNMP.
Are you affected by CVE-2015-6029?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
