ID

VAR-201508-0310


CVE

CVE-2015-2871


TITLE

Chiyu Technology fingerprint access control contains multiple vulnerabilities

Trust: 0.8

sources: CERT/CC: VU#360431

DESCRIPTION

Chiyu BF-660C fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify communication configuration settings via a request to net.htm, a different vulnerability than CVE-2015-5618. Chiyu The fingerprint authentication entrance / exit management system avoids authentication and sets the communication configuration. (1) Read or (2) There are vulnerabilities to be modified. Chiyu BF-660C fingerprint access-control devices is a network fingerprint access control attendance machine from Chiyou. The Chiyu BF-660C fingerprint access-control device has a security hole. An attacker could leverage these issues to gain unauthorized access to the affected application, execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, or generate authentication credentials to impersonate legitimate users

Trust: 3.15

sources: NVD: CVE-2015-2871 // CERT/CC: VU#360431 // JVNDB: JVNDB-2015-003959 // CNVD: CNVD-2015-05152 // BID: 76140

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-05152

AFFECTED PRODUCTS

vendor:chiyumodel:bf-660cscope: - version: -

Trust: 2.0

vendor:chiyumodel:bf-660cscope:eqversion:*

Trust: 1.0

vendor:chiyumodel: - scope: - version: -

Trust: 0.8

vendor:chiyumodel:bf-630wscope: - version: -

Trust: 0.6

vendor:chiyumodel:bf-630scope: - version: -

Trust: 0.6

vendor:chiyumodel:technology bf-660cscope:eqversion:0

Trust: 0.3

vendor:chiyumodel:technology bf-630wscope:eqversion:0

Trust: 0.3

vendor:chiyumodel:technology bf-630scope:eqversion:0

Trust: 0.3

sources: CERT/CC: VU#360431 // CNVD: CNVD-2015-05152 // BID: 76140 // JVNDB: JVNDB-2015-003959 // CNNVD: CNNVD-201507-843 // NVD: CVE-2015-2871

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-2871
value: HIGH

Trust: 1.0

NVD: CVE-2015-2871
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-05152
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201507-843
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2015-2871
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-05152
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2015-05152 // JVNDB: JVNDB-2015-003959 // CNNVD: CNNVD-201507-843 // NVD: CVE-2015-2871

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.8

sources: JVNDB: JVNDB-2015-003959 // NVD: CVE-2015-2871

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201507-843

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201507-843

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003959

PATCH

title:Product Galleryurl:http://www.chiyu-t.com.tw/pdt_list.asp?area=46&cat=151

Trust: 0.8

sources: JVNDB: JVNDB-2015-003959

EXTERNAL IDS

db:CERT/CCid:VU#360431

Trust: 4.1

db:NVDid:CVE-2015-2871

Trust: 3.3

db:JVNid:JVNVU91647568

Trust: 0.8

db:JVNDBid:JVNDB-2015-003959

Trust: 0.8

db:CNVDid:CNVD-2015-05152

Trust: 0.6

db:CNNVDid:CNNVD-201507-843

Trust: 0.6

db:BIDid:76140

Trust: 0.3

sources: CERT/CC: VU#360431 // CNVD: CNVD-2015-05152 // BID: 76140 // JVNDB: JVNDB-2015-003959 // CNNVD: CNNVD-201507-843 // NVD: CVE-2015-2871

REFERENCES

url:http://www.kb.cert.org/vuls/id/360431

Trust: 3.3

url:http://cwe.mitre.org/data/definitions/80.html

Trust: 0.8

url:http://cwe.mitre.org/data/definitions/288.html

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-2871

Trust: 0.8

url:http://jvn.jp/vu/jvnvu91647568/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-2871

Trust: 0.8

url:http://www.chiyu-t.com.tw

Trust: 0.3

sources: CERT/CC: VU#360431 // CNVD: CNVD-2015-05152 // BID: 76140 // JVNDB: JVNDB-2015-003959 // CNNVD: CNNVD-201507-843 // NVD: CVE-2015-2871

CREDITS

Maxim Rupp

Trust: 0.3

sources: BID: 76140

SOURCES

db:CERT/CCid:VU#360431
db:CNVDid:CNVD-2015-05152
db:BIDid:76140
db:JVNDBid:JVNDB-2015-003959
db:CNNVDid:CNNVD-201507-843
db:NVDid:CVE-2015-2871

LAST UPDATE DATE

2025-04-12T23:04:35.835000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#360431date:2015-07-31T00:00:00
db:CNVDid:CNVD-2015-05152date:2015-08-10T00:00:00
db:BIDid:76140date:2015-07-31T00:00:00
db:JVNDBid:JVNDB-2015-003959date:2015-08-04T00:00:00
db:CNNVDid:CNNVD-201507-843date:2015-08-06T00:00:00
db:NVDid:CVE-2015-2871date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#360431date:2015-07-31T00:00:00
db:CNVDid:CNVD-2015-05152date:2015-08-10T00:00:00
db:BIDid:76140date:2015-07-31T00:00:00
db:JVNDBid:JVNDB-2015-003959date:2015-08-04T00:00:00
db:CNNVDid:CNNVD-201507-843date:2015-07-31T00:00:00
db:NVDid:CVE-2015-2871date:2015-08-01T01:59:12.927