« Volver al listado

CVE-2015-5464

Estado: ModificadaBaja (1.3)—

The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-5464",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.3,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:M/C:P/I:N/A:N",
          "authentication": "MULTIPLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 2.2,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-07-22T10:59:00.083",
  "references": [
    {
      "url": "http://www.safenet-inc.com/technical-support/security-updates/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.safenet-inc.com/technical-support/security-updates/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en HSM de Gemalto Safenet Luna, permite a usuarios remotos autenticados evadir las restricciones destinadas a exportación de claves aprovechando el acceso del (1) crypto-user o (2) crypto-officer a una partición de HSM."
    }
  ],
  "lastModified": "2026-06-17T00:29:10.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gemalto:safenet_luna_g5:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05E6BBBA-998B-4776-BDC7-9A8C21FD2608"
            },
            {
              "criteria": "cpe:2.3:h:gemalto:safenet_luna_pci-e:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "476529DF-0ECB-46FF-BBFB-ADDC17F6F0DF"
            },
            {
              "criteria": "cpe:2.3:h:gemalto:safenet_luna_sa:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FDA8906-A4AA-4F33-BC52-12299FB890B4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "This vulnerability was updated on 7/29/2015 to reflect information supplied by the vendor, per reference link http://www.safenet-inc.com/technical-support/security-updates/",
  "sourceIdentifier": "cve@mitre.org"
}