ID

VAR-201512-0412


CVE

CVE-2015-6361


TITLE

Cisco DPC3939 Code Injection Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-08309 // CNNVD: CNNVD-201512-179

DESCRIPTION

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170. The Cisco DPC3939 (XB3) is a wireless home voice gateway product from Cisco. Cisco DPC3939 (XB3) Router is prone to a command-injection vulnerability. This issue is being tracked by Cisco bug ID CSCuw86170

Trust: 2.52

sources: NVD: CVE-2015-6361 // JVNDB: JVNDB-2015-006389 // CNVD: CNVD-2015-08309 // BID: 78736 // VULHUB: VHN-84322

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-08309

AFFECTED PRODUCTS

vendor:ciscomodel:dpc3939 wireless residential voice gatewayscope:eqversion:121109acmcst_base

Trust: 1.6

vendor:ciscomodel:dpc3939 121109acmcstscope: - version: -

Trust: 0.9

vendor:ciscomodel:dpc3939 wireless residential voice gatewayscope:eqversion:121109acmcst

Trust: 0.8

sources: CNVD: CNVD-2015-08309 // BID: 78736 // JVNDB: JVNDB-2015-006389 // CNNVD: CNNVD-201512-179 // NVD: CVE-2015-6361

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6361
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6361
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-08309
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201512-179
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84322
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6361
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-08309
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-84322
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-08309 // VULHUB: VHN-84322 // JVNDB: JVNDB-2015-006389 // CNNVD: CNNVD-201512-179 // NVD: CVE-2015-6361

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-84322 // JVNDB: JVNDB-2015-006389 // NVD: CVE-2015-6361

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201512-179

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201512-179

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-006389

PATCH

title:cisco-sa-20151208-xb3url:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151208-xb3

Trust: 0.8

sources: JVNDB: JVNDB-2015-006389

EXTERNAL IDS

db:NVDid:CVE-2015-6361

Trust: 3.4

db:BIDid:78736

Trust: 1.0

db:JVNDBid:JVNDB-2015-006389

Trust: 0.8

db:CNNVDid:CNNVD-201512-179

Trust: 0.7

db:CNVDid:CNVD-2015-08309

Trust: 0.6

db:SEEBUGid:SSVID-90151

Trust: 0.1

db:VULHUBid:VHN-84322

Trust: 0.1

sources: CNVD: CNVD-2015-08309 // VULHUB: VHN-84322 // BID: 78736 // JVNDB: JVNDB-2015-006389 // CNNVD: CNNVD-201512-179 // NVD: CVE-2015-6361

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151208-xb3

Trust: 2.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6361

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6361

Trust: 0.8

url:http://www.securityfocus.com/bid/78736

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/web/consumer/support/modem_dpc3939.html#

Trust: 0.3

sources: CNVD: CNVD-2015-08309 // VULHUB: VHN-84322 // BID: 78736 // JVNDB: JVNDB-2015-006389 // CNNVD: CNNVD-201512-179 // NVD: CVE-2015-6361

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 78736

SOURCES

db:CNVDid:CNVD-2015-08309
db:VULHUBid:VHN-84322
db:BIDid:78736
db:JVNDBid:JVNDB-2015-006389
db:CNNVDid:CNNVD-201512-179
db:NVDid:CVE-2015-6361

LAST UPDATE DATE

2025-04-12T22:58:45.410000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-08309date:2015-12-21T00:00:00
db:VULHUBid:VHN-84322date:2015-12-15T00:00:00
db:BIDid:78736date:2015-12-08T00:00:00
db:JVNDBid:JVNDB-2015-006389date:2015-12-16T00:00:00
db:CNNVDid:CNNVD-201512-179date:2015-12-14T00:00:00
db:NVDid:CVE-2015-6361date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-08309date:2015-12-21T00:00:00
db:VULHUBid:VHN-84322date:2015-12-13T00:00:00
db:BIDid:78736date:2015-12-08T00:00:00
db:JVNDBid:JVNDB-2015-006389date:2015-12-16T00:00:00
db:CNNVDid:CNNVD-201512-179date:2015-12-10T00:00:00
db:NVDid:CVE-2015-6361date:2015-12-13T03:59:00.127