« Volver al listado

CVE-2015-5629

Estado: ModificadaMedia (6.8)—

The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-5629",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-09-11T21:59:00.100",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN04644117/index.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000115",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://itunes.apple.com/en/app/japan-connected-free-wi-fi/id810838196?mt=8",
      "tags": [
        "Patch"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.nttbp.jfw",
      "tags": [
        "Patch"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN04644117/index.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000115",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://itunes.apple.com/en/app/japan-connected-free-wi-fi/id810838196?mt=8",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://play.google.com/store/apps/details?id=com.nttbp.jfw",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en la aplicación NTT Broadband Platform Japan Connected-free Wi-Fi 1.6.0 y versiones anteriores para Android y 1.0.2 y versiones anteriores para iOS, permite a atacantes eludir un mecanismo de protección de URL de lista blanca y obtener acceso a la API a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:29:28.747",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ntt-bp:japan_connected-free_wi-fi:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7E3111B7-87D7-4D39-9B5D-FD22995B0303",
              "versionEndIncluding": "1.0.2"
            },
            {
              "criteria": "cpe:2.3:a:ntt-bp:japan_connected-free_wi-fi:*:*:*:*:*:android:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB0B11F1-2072-45D3-915F-338EB3DE3320",
              "versionEndIncluding": "1.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}