ID

VAR-201508-0388


CVE

CVE-2015-3959


TITLE

Belden GarrettCom Magnum 6K and Magnum 10K Runs on the switch MNS Vulnerabilities in which access rights can be obtained in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2015-003988

DESCRIPTION

The firmware in MNS before 4.5.6 on Belden GarrettCom Magnum 6K and Magnum 10K switches has a hardcoded serial-console password for a privileged account, which might allow physically proximate attackers to obtain access by establishing a console session to a nonstandard installation on which this account is enabled, and leveraging knowledge of this password. Supplementary information : CWE Vulnerability type by CWE-798: Use of Hard-coded Credentials ( Using hard-coded credentials ) Has been identified. GarrettCom Magnum 6K and 10K Switches are managed switches from GarrettCom, USA. A security vulnerability exists in GarrettCom Magnum 6K and 10K Switches that allows a local attacker to exploit a vulnerability to bypass security restrictions and perform unauthorized operations. An attacker in physical proximity could exploit this vulnerability to gain access with the enablement of this privileged account and a known password

Trust: 2.52

sources: NVD: CVE-2015-3959 // JVNDB: JVNDB-2015-003988 // CNVD: CNVD-2015-04090 // BID: 75235 // VULHUB: VHN-81920

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-04090

AFFECTED PRODUCTS

vendor:garrettcommodel:magnum 10kscope:lteversion:4.5.5

Trust: 1.0

vendor:garrettcommodel:magnum 6kscope:lteversion:4.5.5

Trust: 1.0

vendor:garrettcommodel:magnum 10kscope:ltversion:4.5.6

Trust: 0.8

vendor:garrettcommodel:magnum 6kscope:ltversion:4.5.6

Trust: 0.8

vendor:garrettcommodel:magnum 6kscope: - version: -

Trust: 0.6

vendor:garrettcommodel:magnum 10kscope: - version: -

Trust: 0.6

vendor:garrettcommodel:magnum 6kscope:eqversion:4.5.5

Trust: 0.6

vendor:garrettcommodel:magnum 10kscope:eqversion:4.5.5

Trust: 0.6

vendor:garrettcommodel:magnum 6kqscope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 6kmscope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 6klscope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 6k8scope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 6k32scope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 6k25scope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 6k16scope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 10ktscope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 10kgscope:eqversion:4.5.5

Trust: 0.3

vendor:garrettcommodel:magnum 6kqscope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 6kmscope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 6klscope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 6k8scope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 6k32scope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 6k25scope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 6k16scope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 10ktscope:neversion:4.5.6

Trust: 0.3

vendor:garrettcommodel:magnum 10kgscope:neversion:4.5.6

Trust: 0.3

sources: CNVD: CNVD-2015-04090 // BID: 75235 // JVNDB: JVNDB-2015-003988 // CNNVD: CNNVD-201506-460 // NVD: CVE-2015-3959

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3959
value: HIGH

Trust: 1.0

NVD: CVE-2015-3959
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-04090
value: LOW

Trust: 0.6

CNNVD: CNNVD-201506-460
value: HIGH

Trust: 0.6

VULHUB: VHN-81920
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-3959
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-04090
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-81920
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-04090 // VULHUB: VHN-81920 // JVNDB: JVNDB-2015-003988 // CNNVD: CNNVD-201506-460 // NVD: CVE-2015-3959

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2015-003988 // NVD: CVE-2015-3959

THREAT TYPE

local

Trust: 0.9

sources: BID: 75235 // CNNVD: CNNVD-201506-460

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201506-460

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003988

PATCH

title:MNS6K R456 Release Notesurl:http://www.garrettcom.com/techsupport/MNS6K_R456_Release_Notes.pdf

Trust: 0.8

title:GarrettCom Magnum 6K and 10K Switches Local Security Bypass Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/60143

Trust: 0.6

sources: CNVD: CNVD-2015-04090 // JVNDB: JVNDB-2015-003988

EXTERNAL IDS

db:NVDid:CVE-2015-3959

Trust: 3.4

db:ICS CERTid:ICSA-15-167-01

Trust: 2.8

db:BIDid:75235

Trust: 2.6

db:JVNDBid:JVNDB-2015-003988

Trust: 0.8

db:CNNVDid:CNNVD-201506-460

Trust: 0.7

db:CNVDid:CNVD-2015-04090

Trust: 0.6

db:VULHUBid:VHN-81920

Trust: 0.1

sources: CNVD: CNVD-2015-04090 // VULHUB: VHN-81920 // BID: 75235 // JVNDB: JVNDB-2015-003988 // CNNVD: CNNVD-201506-460 // NVD: CVE-2015-3959

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-15-167-01

Trust: 2.8

url:http://www.securityfocus.com/bid/75235

Trust: 2.3

url:http://www.garrettcom.com/techsupport/mns6k_r456_release_notes.pdf

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3959

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3959

Trust: 0.8

url:http://www.garrettcom.com/

Trust: 0.3

sources: CNVD: CNVD-2015-04090 // VULHUB: VHN-81920 // BID: 75235 // JVNDB: JVNDB-2015-003988 // CNNVD: CNNVD-201506-460 // NVD: CVE-2015-3959

CREDITS

Ashish Kamble of Qualys Security and Eireann Leverett

Trust: 0.9

sources: BID: 75235 // CNNVD: CNNVD-201506-460

SOURCES

db:CNVDid:CNVD-2015-04090
db:VULHUBid:VHN-81920
db:BIDid:75235
db:JVNDBid:JVNDB-2015-003988
db:CNNVDid:CNNVD-201506-460
db:NVDid:CVE-2015-3959

LAST UPDATE DATE

2025-04-13T23:03:58.904000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-04090date:2015-06-30T00:00:00
db:VULHUBid:VHN-81920date:2016-12-06T00:00:00
db:BIDid:75235date:2015-06-16T00:00:00
db:JVNDBid:JVNDB-2015-003988date:2015-08-05T00:00:00
db:CNNVDid:CNNVD-201506-460date:2015-08-04T00:00:00
db:NVDid:CVE-2015-3959date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-04090date:2015-06-29T00:00:00
db:VULHUBid:VHN-81920date:2015-08-04T00:00:00
db:BIDid:75235date:2015-06-16T00:00:00
db:JVNDBid:JVNDB-2015-003988date:2015-08-05T00:00:00
db:CNNVDid:CNNVD-201506-460date:2015-06-24T00:00:00
db:NVDid:CVE-2015-3959date:2015-08-04T01:59:04.407