« Volver al listado

CVE-2016-7815

Estado: ModificadaMedia (4.2)—

Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-7815",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.2,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "Cybozu, Inc.",
          "product": "Remote Service Manager",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0 to 3.1.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-28T16:59:00.153",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN19241292/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://www.securityfocus.com/bid/95379",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://support.cybozu.com/ja-jp/article/9689",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN19241292/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/95379",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.cybozu.com/ja-jp/article/9689",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network."
    },
    {
      "lang": "es",
      "value": "Remote Service Manager 3.0.0 a 3.1.4 no verifica los certificados de cliente, lo que puede permitir a atacantes remotos acceder a los sistemas de la red."
    }
  ],
  "lastModified": "2026-06-17T00:53:32.860",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cybozu:remote_service_manager:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47986509-3FE7-41FA-B3C2-DEBB1201B005"
            },
            {
              "criteria": "cpe:2.3:a:cybozu:remote_service_manager:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75F82710-0C0B-4F31-A13B-B68C9EAF271B"
            },
            {
              "criteria": "cpe:2.3:a:cybozu:remote_service_manager:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CE5F1F5-6B38-477A-864A-F221FF15607D"
            },
            {
              "criteria": "cpe:2.3:a:cybozu:remote_service_manager:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADCF1218-7F7F-4EC2-BA63-97D28F2EDD03"
            },
            {
              "criteria": "cpe:2.3:a:cybozu:remote_service_manager:3.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D35FA1A5-AE98-4CD5-9766-89A34E00DC8E"
            },
            {
              "criteria": "cpe:2.3:a:cybozu:remote_service_manager:3.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E16EFBA2-9E24-4B8A-8BD2-A808E05B6907"
            },
            {
              "criteria": "cpe:2.3:a:cybozu:remote_service_manager:3.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "880248D2-57EF-4EB4-B3F4-929DF9CA4D54"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}