CVE-2015-2878
HIGHHexis HawkEye G 3.0.1.4912 - Cross-Site Request Forgery via Multiple Endpoints
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2878. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates multiple CSRF vulnerabilities in Hawkeye-G v3.0.1.4912, allowing arbitrary account creation, sensor setting modifications, and whitelisting of malware MD5 hashes via crafted POST requests.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/json; turn off the (2) Url matching, (3) DNS Inject, or (4) IP Redirect Sensor in a request to interface/rest/dpi/setEnabled/1; or (5) perform whitelisting of malware MD5 hash IDs via the id parameter to interface/rest/md5-threats/whitelist.
Exploits (1)
This exploit demonstrates multiple CSRF vulnerabilities in Hawkeye-G v3.0.1.4912, allowing arbitrary account creation, sensor setting modifications, and whitelisting of malware MD5 hashes via crafted POST requests.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H