CVE Listesine Dön
CVE-2015-5477 CISA KEV · Aktif SömürülüyorOtomatik saldırıya uygun · CISA

Vulnerability in N/a

CVSS Skor

7.5

EPSS İhtimal

%99.4

Risk Skoru

14.9

Yayın

11 yıl önce

Resmî yama doğrulandı

Etkilenen ürün ve sürüm için yayımlanan güvenlik güncellemesini uygulayın.

Envanterimdeki Etkisi

Yalnızca hesabınıza eklediğiniz kişisel ürünler değerlendirilir; kurumsal envanter burada görünmez.

Oturum kontrol ediliyor…

Zafiyet Açıklaması

DayBreach CVE AI Araştırması

CVE-2015-5477 için toplanan üretici, dağıtım, yama ve güvenlik kaynağı kayıtlarını karşılaştırıp kanıt bağlantılı bir açıklama hazırlayalım.

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

IMPACT — Etkilenen Ürünler ve Yazılımlar

Affected Products

The following products are affected by CVE-2015-5477 vulnerability. Even if our threat engine is aware of the exact versions of the products that are affected, the information is represented below.

IDVENDORPRODUCTACTION
1n/an/a İncele
2juniperjunos İncele
3juniperjunos İncele
4juniperjunos İncele
5juniperjunos İncele
6juniperjunos İncele
7juniperjunos İncele
8juniperjunos İncele
9juniperjunos İncele
10juniperjunos İncele
11juniperjunos İncele
12juniperjunos İncele
13juniperjunos İncele
14juniperjunos İncele
15juniperjunos İncele
16juniperjunos İncele
17juniperjunos İncele
18juniperjunos İncele
19juniperjunos İncele
20juniperjunos İncele
21juniperjunos İncele
22juniperjunos İncele
23juniperj2300 İncele
24juniperj2320 İncele
25juniperj2350 İncele
26juniperj4300 İncele
27juniperj4350 İncele
28juniperj4350 nebs İncele
29juniperj6300 İncele
30juniperj635 nebs İncele
31juniperj6350 İncele
32juniperjx-4bri İncele
33juniperjx-4ct1e1 İncele
34junipersrx100 İncele
35junipersrx1400 İncele
36junipersrx1500 İncele
37junipersrx1600 İncele
38junipersrx2300 İncele
39junipersrx300 İncele
40junipersrx320 İncele
41junipersrx340 İncele
42junipersrx3400 İncele
43junipersrx345 İncele
44junipersrx3600 İncele
45junipersrx380 İncele
46junipersrx400 İncele
47junipersrx4100 İncele
48junipersrx4120 İncele
49junipersrx4200 İncele
50junipersrx4300 İncele
51junipersrx440 İncele
52junipersrx4600 İncele
53junipersrx4700 İncele
54junipersrx5400 İncele
55junipersrx550 hm İncele
56junipersrx5600 İncele
57junipersrx5800 İncele
58junipersrx650 İncele
59fedoraprojectfedora İncele
60fedoraprojectfedora İncele
61redhatenterprise linux İncele
62redhatenterprise linux İncele
63redhatenterprise linux İncele
64redhatenterprise linux aus İncele
65redhatenterprise linux aus İncele
66redhatenterprise linux aus İncele
67debiandebian linux İncele
68debiandebian linux İncele
69oraclevm server İncele
70oraclesolaris İncele
71oraclesolaris İncele
72hphp-ux İncele
73hphp-ux İncele
74hphp-ux İncele
75canonicalubuntu linux İncele
76netappclustered data ontap İncele
77appleos x server İncele
78hpedns İncele
79hpedns İncele
80hpopenvms İncele
81hpevcx İncele
82hpej9668a İncele
83hpej9669a İncele
84hpej9672a İncele
85hpejc516a İncele
86hpejc517a İncele
87hpejc518a İncele
88hpejd023a İncele
89hpejd024a İncele
90hpejd025a İncele
91hpejd026a İncele
92hpejd027a İncele
93hpejd028a İncele
94hpejd029a İncele
95hpeje252a İncele
96hpeje253a İncele
97hpeje254a İncele
98hpeje340a İncele
99hpeje341a İncele
100hpeje342a İncele
101hpeje355a İncele
102suselinux enterprise debuginfo İncele
103opensuseevergreen İncele
104opensuseopensuse İncele
105opensuseopensuse İncele
106suselinux enterprise desktop İncele
107suselinux enterprise desktop İncele
108suselinux enterprise server İncele
109suselinux enterprise server İncele
110suselinux enterprise server İncele
111suselinux enterprise software development kit İncele
112suselinux enterprise software development kit İncele
113iscbind İncele
114iscbind İncele
115iscbind İncele
Total Affected Vendor: 14|Products: 115

RED HAT CSAF/VEX — Ürün Etki Kontrolü

Red Hat bu CVE için henüz bir CSAF/VEX etki kaydı yayımlamamış. Bu durum “etkilenmiyor” anlamına gelmez.

SCORING — CVSS Çoklu Kaynak Skoru

CVSS Scores

The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and display CVSS scores from various sources for each CVE.

SCOREVERSIONSEVERITYVECTORSOURCE
7.8CVSS V2—AV:N/AC:L/Au:N/C:N/I:N/A:CNVD
7.5CVSS V31HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNVD
7.5CVSS V3_1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVE ADP

Yama ve İyileştirme Rehberi (Solution)

Solution & Remediation Advisory

Yama doğrulandı

1 doğrulanmış yama veya düzeltilmiş sürüm kanıtı bulundu.

nvd

NVD tarafından Patch olarak etiketlenmiş referans

Kaynağı aç
canonical

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Etkilenen ürün ve sürümü yukarıdaki kaynak kanıtlarıyla doğrulayın.
İnternete açık servislerde erişimi kısıtlayın ve ağ segmentasyonu uygulayın.
Kanıtta belirtilen resmî güncellemeyi yalnızca eşleşen ürün ve sürüme uygulayın.
Sunucu günlüklerini ve ağ uçlarını anormal çalıştırma belirtileri için izleyin.

Public exploit ve aktif sömürü durumu

Doğrulanmış exploit istihbaratı

Bu CVE CISA KEV kataloğunda aktif sömürülen olarak işaretli; ancak henüz doğrulanmış, indirilebilir bir public PoC veya Metasploit modülü bulunamadı. Aktif sömürü kanıtı public exploit kodu bulunduğu anlamına gelmez.

Zafiyet Dağılımı ve Saldırı Kalıpları (CWE & CAPEC)

CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2015-5477 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2015-5477 weaknesses.

Saldırı Vektörü ve Erişilebilirlik Karakteristiği

ErişimAğ üzerinden
YetkiGerekmiyor
KullanıcıGerekmiyor

Resmi Kaynaklar ve Danışma Bültenleri

CVSS Vektör Radar Grafiği

7.5 / 10
Attack VectorNetworkComplexityLowPrivilegesNoneUser Interact.NoneConfidentialityLowIntegrityNoneAvailabilityHigh

Vulnerability Scoring Details

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorNetwork (Ağ)
Attack ComplexityLow (Düşük)
Privileges RequiredNone (Gerekmiyor)
User InteractionNone (Gerekmiyor)
Confidentiality (Gizlilik)Low (Düşük)
Integrity (Bütünlük)None (Yok)
Availability (Erişilebilirlik)High (Yüksek)

Yama doğrulandı

1 doğrulanmış yama veya düzeltilmiş sürüm kanıtı bulundu.

Üreticiyi takip et

N
n/a logo
n/a
J
juniper logo
juniper
R
redhat logo
redhat
D
debian logo
debian
O
oracle logo
oracle

Zafiyet Türü (CWE & CAPEC)

İlgili Benzer Açıklar

Bu açığı API ile alın

Etkilenen ürünler, sürüm aralıkları, istismar durumu ve yama bilgisi tek istekte; ücretsiz anahtarla.

curl -H "x-api-key: $DAYBREACH_API_KEY" \
  "https://api.enginteksut.com.tr/api/v1/intel/cves/CVE-2015-5477"