ID

VAR-201508-0309


CVE

CVE-2015-2870


TITLE

Chiyu Technology fingerprint access control contains multiple vulnerabilities

Trust: 0.8

sources: CERT/CC: VU#360431

DESCRIPTION

Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element. Chiyu BF-630, BF-630W and BF-660C are products of Chiyu. Both the BF-630 and BF-630W are networked fingerprint access controllers. BF-660C is a network type fingerprint access control attendance machine. An attacker could leverage these issues to gain unauthorized access to the affected application, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or generate authentication credentials to impersonate legitimate users

Trust: 3.15

sources: NVD: CVE-2015-2870 // CERT/CC: VU#360431 // JVNDB: JVNDB-2015-003958 // CNVD: CNVD-2015-05125 // BID: 76140

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-05125

AFFECTED PRODUCTS

vendor:chiyutwmodel:bf-630scope:eqversion: -

Trust: 1.6

vendor:chiyutwmodel:bf-630wscope:eqversion: -

Trust: 1.6

vendor:chiyutwmodel:bf-660cscope:eqversion: -

Trust: 1.6

vendor:chiyumodel:bf-660cscope: - version: -

Trust: 1.4

vendor:chiyumodel:bf-630wscope: - version: -

Trust: 1.4

vendor:chiyumodel:bf-630scope: - version: -

Trust: 1.4

vendor:chiyumodel: - scope: - version: -

Trust: 0.8

vendor:chiyumodel:technology bf-660cscope:eqversion:0

Trust: 0.3

vendor:chiyumodel:technology bf-630wscope:eqversion:0

Trust: 0.3

vendor:chiyumodel:technology bf-630scope:eqversion:0

Trust: 0.3

sources: CERT/CC: VU#360431 // CNVD: CNVD-2015-05125 // BID: 76140 // JVNDB: JVNDB-2015-003958 // CNNVD: CNNVD-201507-842 // NVD: CVE-2015-2870

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-2870
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-2870
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-05125
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201507-842
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2015-2870
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-05125
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-05125 // JVNDB: JVNDB-2015-003958 // CNNVD: CNNVD-201507-842 // NVD: CVE-2015-2870

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.8

sources: JVNDB: JVNDB-2015-003958 // NVD: CVE-2015-2870

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201507-842

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201507-842

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003958

PATCH

title:Product Galleryurl:http://www.chiyu-t.com.tw/pdt_list.asp?area=46&cat=151

Trust: 0.8

sources: JVNDB: JVNDB-2015-003958

EXTERNAL IDS

db:CERT/CCid:VU#360431

Trust: 4.1

db:NVDid:CVE-2015-2870

Trust: 3.3

db:JVNid:JVNVU91647568

Trust: 0.8

db:JVNDBid:JVNDB-2015-003958

Trust: 0.8

db:CNVDid:CNVD-2015-05125

Trust: 0.6

db:CNNVDid:CNNVD-201507-842

Trust: 0.6

db:BIDid:76140

Trust: 0.3

sources: CERT/CC: VU#360431 // CNVD: CNVD-2015-05125 // BID: 76140 // JVNDB: JVNDB-2015-003958 // CNNVD: CNNVD-201507-842 // NVD: CVE-2015-2870

REFERENCES

url:http://www.kb.cert.org/vuls/id/360431

Trust: 3.3

url:http://cwe.mitre.org/data/definitions/80.html

Trust: 0.8

url:http://cwe.mitre.org/data/definitions/288.html

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-2870

Trust: 0.8

url:http://jvn.jp/vu/jvnvu91647568/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-2870

Trust: 0.8

url:http://www.chiyu-t.com.tw

Trust: 0.3

sources: CERT/CC: VU#360431 // CNVD: CNVD-2015-05125 // BID: 76140 // JVNDB: JVNDB-2015-003958 // CNNVD: CNNVD-201507-842 // NVD: CVE-2015-2870

CREDITS

Maxim Rupp

Trust: 0.3

sources: BID: 76140

SOURCES

db:CERT/CCid:VU#360431
db:CNVDid:CNVD-2015-05125
db:BIDid:76140
db:JVNDBid:JVNDB-2015-003958
db:CNNVDid:CNNVD-201507-842
db:NVDid:CVE-2015-2870

LAST UPDATE DATE

2025-04-12T23:04:35.800000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#360431date:2015-07-31T00:00:00
db:CNVDid:CNVD-2015-05125date:2015-08-05T00:00:00
db:BIDid:76140date:2015-07-31T00:00:00
db:JVNDBid:JVNDB-2015-003958date:2015-08-04T00:00:00
db:CNNVDid:CNNVD-201507-842date:2015-08-03T00:00:00
db:NVDid:CVE-2015-2870date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#360431date:2015-07-31T00:00:00
db:CNVDid:CNVD-2015-05125date:2015-08-05T00:00:00
db:BIDid:76140date:2015-07-31T00:00:00
db:JVNDBid:JVNDB-2015-003958date:2015-08-04T00:00:00
db:CNNVDid:CNNVD-201507-842date:2015-07-31T00:00:00
db:NVDid:CVE-2015-2870date:2015-08-01T01:59:11.943