CVE-2015-6237
Last modified
CVE-2015-6237 is a vulnerability of currently unknown severity. The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands.". EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tripwire | Ip360 | 7.2.2 |
| Tripwire | Ip360 | 7.2.4 |
| Tripwire | Ip360 | 7.2.5 |
References
- http://seclists.org/fulldisclosure/2015/Oct/20Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2015/Oct/20Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6237?
How severe is CVE-2015-6237?
How do I fix CVE-2015-6237?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-6231Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-6232Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-6233Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-6234Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-6235Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-6236Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-6238Multiple cross-site scripting (XSS) vulnerabilities in the G…
- CVE-2015-6240The chroot, jail, and zone connection plugins in ansible bef…
- CVE-2015-6241The proto_tree_add_bytes_item function in epan/proto.c in th…
- CVE-2015-6242The wmem_block_split_free_chunk function in epan/wmem/wmem_a…
- CVE-2015-6243The dissector-table implementation in epan/packet.c in Wires…
- CVE-2015-6244The dissect_zbee_secure function in epan/dissectors/packet-z…
Are you affected by CVE-2015-6237?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
