ID

VAR-201512-0010


CVE

CVE-2015-7906


TITLE

plural LOYTEC Vulnerability to read password hash backup file on device

Trust: 0.8

sources: JVNDB: JVNDB-2015-006496

DESCRIPTION

LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backup file via unspecified vectors. plural LOYTEC The device contains a vulnerability that allows it to read password hash backup files.A third party may be able to read password hash backup files. LOYTEC LIP devices are IP network router devices from LOYTEC, Germany. LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, LIP-ME201 devices have information disclosure vulnerabilities. LOYTEC Router is prone to an arbitrary file-download vulnerability. An attacker can exploit this issue to download backup files. Information obtained may aid in further attacks. The following products and versions are affected: LOYTEC LIP-3ECTB version 6.0.1, LINX-100, LVIS-3E100, LIP-ME201

Trust: 2.52

sources: NVD: CVE-2015-7906 // JVNDB: JVNDB-2015-006496 // CNVD: CNVD-2015-08492 // BID: 78807 // VULHUB: VHN-85867

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-08492

AFFECTED PRODUCTS

vendor:loytecmodel:l-switch and l-ipscope:eqversion:6.0.1

Trust: 2.4

vendor:loytecmodel:lip-me201scope: - version: -

Trust: 1.4

vendor:loytecmodel:lvis-3e100scope: - version: -

Trust: 1.4

vendor:loytecmodel:linx-100scope: - version: -

Trust: 1.4

vendor:loytecmodel:lip-3ectbscope: - version: -

Trust: 0.8

vendor:loytecmodel:lip-3ectbscope:eqversion:6.1

Trust: 0.6

vendor:loytecmodel:lvis-3e100scope:eqversion:0

Trust: 0.3

vendor:loytecmodel:lip-me201scope:eqversion:0

Trust: 0.3

vendor:loytecmodel:lip-3ectbscope:eqversion:6.0.1

Trust: 0.3

vendor:loytecmodel:linx-100scope:eqversion:0

Trust: 0.3

vendor:loytecmodel:lip-3ectbscope:neversion:6.0.2

Trust: 0.3

sources: CNVD: CNVD-2015-08492 // BID: 78807 // JVNDB: JVNDB-2015-006496 // CNNVD: CNNVD-201512-555 // NVD: CVE-2015-7906

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-7906
value: HIGH

Trust: 1.0

NVD: CVE-2015-7906
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-08492
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201512-555
value: CRITICAL

Trust: 0.6

VULHUB: VHN-85867
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-7906
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-08492
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-85867
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-08492 // VULHUB: VHN-85867 // JVNDB: JVNDB-2015-006496 // CNNVD: CNNVD-201512-555 // NVD: CVE-2015-7906

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.9

sources: VULHUB: VHN-85867 // JVNDB: JVNDB-2015-006496 // NVD: CVE-2015-7906

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201512-555

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201512-555

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-006496

PATCH

title:L-Switch and L-IP Firmware 6.0.2 for LS-xCB, LIP-xECTB, and LIP-xECRB Devicesurl:https://www.loytec.com/support/download/cat_view/36-products?gid=92

Trust: 0.8

title:Multiple LOYTEC Fixes for device trust management vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=59322

Trust: 0.6

sources: JVNDB: JVNDB-2015-006496 // CNNVD: CNNVD-201512-555

EXTERNAL IDS

db:NVDid:CVE-2015-7906

Trust: 3.4

db:ICS CERTid:ICSA-15-342-02

Trust: 3.4

db:JVNDBid:JVNDB-2015-006496

Trust: 0.8

db:CNNVDid:CNNVD-201512-555

Trust: 0.7

db:CNVDid:CNVD-2015-08492

Trust: 0.6

db:BIDid:78807

Trust: 0.4

db:VULHUBid:VHN-85867

Trust: 0.1

sources: CNVD: CNVD-2015-08492 // VULHUB: VHN-85867 // BID: 78807 // JVNDB: JVNDB-2015-006496 // CNNVD: CNNVD-201512-555 // NVD: CVE-2015-7906

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-15-342-02

Trust: 3.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-7906

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-7906

Trust: 0.8

url:https://www.loytec.com/

Trust: 0.3

sources: CNVD: CNVD-2015-08492 // VULHUB: VHN-85867 // BID: 78807 // JVNDB: JVNDB-2015-006496 // CNNVD: CNNVD-201512-555 // NVD: CVE-2015-7906

CREDITS

Maxim Rupp

Trust: 0.3

sources: BID: 78807

SOURCES

db:CNVDid:CNVD-2015-08492
db:VULHUBid:VHN-85867
db:BIDid:78807
db:JVNDBid:JVNDB-2015-006496
db:CNNVDid:CNNVD-201512-555
db:NVDid:CVE-2015-7906

LAST UPDATE DATE

2025-04-12T23:08:59.574000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-08492date:2015-12-28T00:00:00
db:VULHUBid:VHN-85867date:2015-12-21T00:00:00
db:BIDid:78807date:2015-12-08T00:00:00
db:JVNDBid:JVNDB-2015-006496date:2015-12-22T00:00:00
db:CNNVDid:CNNVD-201512-555date:2015-12-22T00:00:00
db:NVDid:CVE-2015-7906date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-08492date:2015-12-28T00:00:00
db:VULHUBid:VHN-85867date:2015-12-21T00:00:00
db:BIDid:78807date:2015-12-08T00:00:00
db:JVNDBid:JVNDB-2015-006496date:2015-12-22T00:00:00
db:CNNVDid:CNNVD-201512-555date:2015-12-22T00:00:00
db:NVDid:CVE-2015-7906date:2015-12-21T11:59:08.143