{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-23T00:28:09.936","vulnerabilities":[{"cve":{"id":"CVE-2015-0985","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2015-03-31T01:59:37.693","lastModified":"2025-04-12T10:46:40.837","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to hijack the authentication of admins for requests that modify the default user's password via a GET request."},{"lang":"es","value":"Vulnerabilidad de CSRF en el sistema operativo XZERES 442SR en las turbinas de aire 442SR permite a atacantes remotos secuestrar la autenticación de administradores para solicitudes que modifican la contraseña del usuario por defecto a través de una solicitud GET."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:xzeres:442sr_os:*:*:*:*:*:*:*:*","matchCriteriaId":"84AAA463-3D2C-4480-B0F7-480F67FFF636"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:xzeres:442sr:*:*:*:*:*:*:*:*","matchCriteriaId":"94DBA981-971C-470A-9ECB-7DC9D58439B2"}]}]}],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-076-01","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-15-076-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}]}}]}