Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:MISC:SAM-ACTQ-MULTI

Severity

Medium

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

Samsung Security Manager ActiveMQ Broker Service Security Bypass

Release Date

2015/05/25

Update Number

2499

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: Samsung Security Manager ActiveMQ Broker Service Security Bypass


This signature detects attempts to exploit a known vulnerability in Samsung Security Manager. A successful attack can lead to security bypass within the context of the running service.

Extended Description

Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE request.

Affected Products

  • samsung samsung_security_manager 1.30

References

  • CVE: CVE-2015-3435
  • URL: http://www.zerodayinitiative.com/advisories/zdi-15-041/
  • URL: http://www.zerodayinitiative.com/advisories/zdi-15-157/
  • URL: http://www.zerodayinitiative.com/advisories/zdi-15-156/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out