CVE-2015-0985 Vulnerability Details
/
/
/
CVE-2015-0985 Metadata Quick Info
CVE Published: 31/03/2015 |
CVE Updated: 06/08/2024 |
CVE Year: 2015
Source: icscert |
Vendor: n/a |
Product: n/a
Status : PUBLISHED
CVE-2015-0985 Description
Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of admins for requests that modify the default user\'s password via a GET request.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: n/a
Source: n/a
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).