← Vulnerability feed

Vulnerability record · CVE-2015-2284 · published 24 March 2015

CVE-2015-2284: SolarWinds Firewall Security Manager userlogin.jsp privilege escalation and code execution

Solarwinds · Firewall Security Manager

SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 contains a flaw in userlogin.jsp related to client session handling that lets remote attackers gain privileges and execute arbitrary code. The vulnerability is network-reachable and requires no authentication, making it a serious pre-auth risk for exposed FSM instances.

10.0 CVSS 2.0 High EPSS 73% · top 0.5% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10 and very high EPSS probability makes this an urgent patching priority despite no KEV listing.

What it is

SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 contains a flaw in userlogin.jsp related to client session handling that lets remote attackers gain privileges and execute arbitrary code. The vulnerability is network-reachable and requires no authentication, making it a serious pre-auth risk for exposed FSM instances.

Impact

An unauthenticated remote attacker can escalate privileges and execute arbitrary code on the FSM server, potentially taking full control of the host and any managed firewall data.

Attack surface

Reached over the network via HTTP to userlogin.jsp; the CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged beyond a patch advisory, but EPSS is very high at 0.73457 (99.4th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade SolarWinds Firewall Security Manager to 6.6.5 HotFix1 or later immediately.
  • Restrict network access to the FSM web interface to trusted management networks only.
  • Place FSM behind a reverse proxy or VPN and block direct internet exposure of userlogin.jsp.
  • Audit FSM logs for anomalous requests to userlogin.jsp and unexpected session or privilege changes.
  • Rotate credentials and review accounts for signs of unauthorized privilege use after patching.

Detection

  • Monitor web server and FSM logs for unusual or repeated requests to userlogin.jsp, especially from untrusted sources.
  • Alert on unexpected process creation or command execution originating from the FSM service account.
  • Track authentication and session events for privilege changes or logins that do not match normal admin patterns.
  • Use network monitoring to detect scanning or exploitation attempts against the FSM management port.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-2284 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2015-2284), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.