ID

VAR-201512-0415


CVE

CVE-2015-6378


TITLE

Cisco Model DPQ3925 with EDVA Device cross-site request forgery vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-006399

DESCRIPTION

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943. The Cisco DPQ3925 devices are a wireless router device from Cisco. Allow remote attackers to hijack the authentication of any user identity. Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible. This issue is being tracked by Cisco Bug ID's CSCuv05430 and CSCuv05943. Cisco Model DPQ3925 8x4 DOCSIS 3.0 Wireless Residential Gateway with Embedded Digital Voice Adapter (EDVA) is vulnerable

Trust: 2.52

sources: NVD: CVE-2015-6378 // JVNDB: JVNDB-2015-006399 // CNVD: CNVD-2015-08383 // BID: 79050 // VULHUB: VHN-84339

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-08383

AFFECTED PRODUCTS

vendor:ciscomodel:dpq3925 8x4 docsis 3.0 wireless residential gateway with embedded digital voice adapterscope:eqversion:5.5.2

Trust: 1.6

vendor:ciscomodel:model dpq3925 8x4 docsis 3.0 wireless residential gateway with edvascope:eqversion:5.5.2

Trust: 0.8

vendor:ciscomodel:dpq3925 devices with edvascope:eqversion:5.5.2

Trust: 0.6

vendor:ciscomodel:model dpq3925 docsis wireless residential gatewayscope:eqversion:8x43.00

Trust: 0.3

sources: CNVD: CNVD-2015-08383 // BID: 79050 // JVNDB: JVNDB-2015-006399 // CNNVD: CNNVD-201512-402 // NVD: CVE-2015-6378

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-6378
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-6378
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-08383
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201512-402
value: MEDIUM

Trust: 0.6

VULHUB: VHN-84339
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-6378
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-08383
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-84339
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-08383 // VULHUB: VHN-84339 // JVNDB: JVNDB-2015-006399 // CNNVD: CNNVD-201512-402 // NVD: CVE-2015-6378

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-84339 // JVNDB: JVNDB-2015-006399 // NVD: CVE-2015-6378

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201512-402

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201512-402

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-006399

PATCH

title:cisco-sa-20151208-gatewayurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151208-gateway

Trust: 0.8

title:Cisco DPQ3925 Fixing measures for device cross-site request forgery vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=59217

Trust: 0.6

sources: JVNDB: JVNDB-2015-006399 // CNNVD: CNNVD-201512-402

EXTERNAL IDS

db:NVDid:CVE-2015-6378

Trust: 3.4

db:SECTRACKid:1034345

Trust: 1.1

db:JVNDBid:JVNDB-2015-006399

Trust: 0.8

db:CNNVDid:CNNVD-201512-402

Trust: 0.7

db:CNVDid:CNVD-2015-08383

Trust: 0.6

db:BIDid:79050

Trust: 0.4

db:VULHUBid:VHN-84339

Trust: 0.1

sources: CNVD: CNVD-2015-08383 // VULHUB: VHN-84339 // BID: 79050 // JVNDB: JVNDB-2015-006399 // CNNVD: CNNVD-201512-402 // NVD: CVE-2015-6378

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20151208-gateway

Trust: 2.6

url:http://www.securitytracker.com/id/1034345

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-6378

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-6378

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2015-08383 // VULHUB: VHN-84339 // BID: 79050 // JVNDB: JVNDB-2015-006399 // CNNVD: CNNVD-201512-402 // NVD: CVE-2015-6378

CREDITS

Cisco

Trust: 0.3

sources: BID: 79050

SOURCES

db:CNVDid:CNVD-2015-08383
db:VULHUBid:VHN-84339
db:BIDid:79050
db:JVNDBid:JVNDB-2015-006399
db:CNNVDid:CNNVD-201512-402
db:NVDid:CVE-2015-6378

LAST UPDATE DATE

2025-04-12T23:25:48.912000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-08383date:2015-12-22T00:00:00
db:VULHUBid:VHN-84339date:2017-09-13T00:00:00
db:BIDid:79050date:2015-12-08T00:00:00
db:JVNDBid:JVNDB-2015-006399date:2015-12-16T00:00:00
db:CNNVDid:CNNVD-201512-402date:2015-12-14T00:00:00
db:NVDid:CVE-2015-6378date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-08383date:2015-12-22T00:00:00
db:VULHUBid:VHN-84339date:2015-12-14T00:00:00
db:BIDid:79050date:2015-12-08T00:00:00
db:JVNDBid:JVNDB-2015-006399date:2015-12-16T00:00:00
db:CNNVDid:CNNVD-201512-402date:2015-12-14T00:00:00
db:NVDid:CVE-2015-6378date:2015-12-14T03:59:00.117