CVE-2015-5372
Status: ModifiedMedium (5)—
The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.87%
- Percentile among all scored CVEs: 58
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-287
References
- http://blog.csnc.ch/2015/09/saml-sp-authentication-bypass-vulnerability-in-nevisauth
- http://packetstormsecurity.com/files/133628/nevisAuth-Authentication-Bypass.html
- http://seclists.org/fulldisclosure/2015/Sep/87
- http://www.csnc.ch/misc/files/advisories/CVE-2015-5372_AdNovum_nevisAuth_Authentication_Bypass.txt
- http://www.securityfocus.com/archive/1/536508/100/0/threaded
- http://blog.csnc.ch/2015/09/saml-sp-authentication-bypass-vulnerability-in-nevisauth
- http://packetstormsecurity.com/files/133628/nevisAuth-Authentication-Bypass.html
- http://seclists.org/fulldisclosure/2015/Sep/87
- http://www.csnc.ch/misc/files/advisories/CVE-2015-5372_AdNovum_nevisAuth_Authentication_Bypass.txt
- http://www.securityfocus.com/archive/1/536508/100/0/threaded
Raw JSON (NVD)
Show
{
"id": "CVE-2015-5372",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-09-28T16:59:05.617",
"references": [
{
"url": "http://blog.csnc.ch/2015/09/saml-sp-authentication-bypass-vulnerability-in-nevisauth",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/133628/nevisAuth-Authentication-Bypass.html",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2015/Sep/87",
"source": "cve@mitre.org"
},
{
"url": "http://www.csnc.ch/misc/files/advisories/CVE-2015-5372_AdNovum_nevisAuth_Authentication_Bypass.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/536508/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://blog.csnc.ch/2015/09/saml-sp-authentication-bypass-vulnerability-in-nevisauth",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/133628/nevisAuth-Authentication-Bypass.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2015/Sep/87",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.csnc.ch/misc/files/advisories/CVE-2015-5372_AdNovum_nevisAuth_Authentication_Bypass.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/536508/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The SAML 2.0 implementation in AdNovum nevisAuth 4.13.0.0 before 4.18.3.1, when using SAML POST-Binding, does not match all attributes of the X.509 certificate embedded in the assertion against the certificate from the identity provider (IdP), which allows remote attackers to inject arbitrary SAML assertions via a crafted certificate."
},
{
"lang": "es",
"value": "Vulnerabilidad en la implementación SAML 2.0 en AdNovum nevisAuth 4.13.0.0 en versiones anteriores a 4.18.3.1, cuando se usa SAML POST-Binding, no encuentra todos los atributos del certificado embebido en la aserción contra el certificado del proveedor de identidad (IdP), lo que permite a atacantes remotos inyectar aserciones SAML arbitrartias a través de un certificado manipulado."
}
],
"lastModified": "2026-06-17T00:29:02.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adnovum:nevisauth:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C42D45F-BB76-4B41-A867-B0C2E777A84B",
"versionEndIncluding": "4.18.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}