{ "schema_version": "1.4.0", "id": "GHSA-qmrg-fwhw-r3r5", "modified": "2022-05-17T03:28:22Z", "published": "2022-05-17T03:28:22Z", "aliases": [ "CVE-2015-2902" ], "details": "HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-2902" }, { "type": "WEB", "url": "https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c04850932" }, { "type": "WEB", "url": "http://www.kb.cert.org/vuls/id/350508" }, { "type": "WEB", "url": "http://www.securitytracker.com/id/1034078" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-11-04T03:59:00Z" } }