CVE-2015-4667
Description
Multiple hardcoded credentials in Xsuite 2.x.
In plain language
AI Worth attentionIf your business runs xsuite 2.x, act soon: anyone who can reach it over the network may be able to take it over using built-in passwords.
CVE-2015-4667 is an unauthenticated network-accessible hardcoded-credential flaw in xsuite 2.x that enables unrestricted system access.
What to do now
- Check whether any server or appliance in your business runs xsuite 2.x and whether it can be reached over your network.
- There is no confirmed fixed version available; ask the xsuite supplier for a supported security update or replacement.
- Until then, block unneeded access to xsuite, especially from the internet, and allow only trusted administrators to reach it.
- Review xsuite access records for unfamiliar logins and investigate any unexpected administrator activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-4667 and every CVE in our database. Create a free account — no credit card required.
Create Free Account