CVE-2015-6420
CRITICALApache Commons Collections < 3.2.2 and < 4.1 - Remote Code Execution via Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-6420. PoCs published by Leeziao.
AI-analyzed exploit summary This repository contains a working PoC for CVE-2015-6420, a Java deserialization vulnerability. The exploit leverages Apache Commons Collections to construct a malicious payload that executes arbitrary commands via a chain of transformers, demonstrating RCE through deserialization.
Description
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Exploits (1)
This repository contains a working PoC for CVE-2015-6420, a Java deserialization vulnerability. The exploit leverages Apache Commons Collections to construct a malicious payload that executes arbitrary commands via a chain of transformers, demonstrating RCE through deserialization.
References (12)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H