CVE-2015-2952
Status: ModifiedMedium (6.5)—
The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and CVE-2015-2958.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.18%
- Percentile among all scored CVEs: 67
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (3)
CWEs
- CWE-284
References
- http://jvn.jp/en/jp/JVN19732015/995646/index.html
- http://jvn.jp/en/jp/JVN19732015/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000077
- http://www.securityfocus.com/bid/75184
- http://jvn.jp/en/jp/JVN19732015/995646/index.html
- http://jvn.jp/en/jp/JVN19732015/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2015-000077
- http://www.securityfocus.com/bid/75184
Raw JSON (NVD)
Show
{
"id": "CVE-2015-2952",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": true,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "vultures@jpcert.or.jp",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-06-13T15:59:02.497",
"references": [
{
"url": "http://jvn.jp/en/jp/JVN19732015/995646/index.html",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://jvn.jp/en/jp/JVN19732015/index.html",
"tags": [
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000077",
"tags": [
"Vendor Advisory"
],
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://www.securityfocus.com/bid/75184",
"source": "vultures@jpcert.or.jp"
},
{
"url": "http://jvn.jp/en/jp/JVN19732015/995646/index.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvn.jp/en/jp/JVN19732015/index.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000077",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/75184",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticated users to bypass intended access restrictions and modify administrative credentials via unspecified vectors, a different vulnerability than CVE-2015-2953 and CVE-2015-2958."
},
{
"lang": "es",
"value": "La funcionalidad de la gestión de información del usuario en Igreks MilkyStep Light 0.94 y anteriores y Professional 1.82 y anteriores permite a usuarios remotos autenticados evadir las restricciones de acceso y modificar las credenciales administrativas a través de vectores no especificados, una vulnerabilidad diferente a CVE-2015-2953 y CVE-2015-2958."
}
],
"lastModified": "2026-06-17T00:25:01.823",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:igreks:milkystep_light:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "717E9862-9C1D-4D2B-AC6A-D3068D198C03",
"versionEndIncluding": "0.94"
},
{
"criteria": "cpe:2.3:a:igreks:milkystep_professional:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BBF034A-902C-4569-BD76-4DF404FB0107",
"versionEndIncluding": "1.82"
},
{
"criteria": "cpe:2.3:a:igreks:milkystep_professional_oem:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA50F9BC-6DD9-4A69-9FBE-5F5B4E4B71DD",
"versionEndIncluding": "1.82"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vultures@jpcert.or.jp"
}