{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T11:05:12Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20150813-CVE-2015-4302","slug":"cisco-sa-20150813-cve-2015-4302","vendor":"Cisco","title":"Cisco FireSIGHT Management Center System Policy Deletion Vulnerability","summary":"A vulnerability in the web interface function to delete a system policy configured in the Cisco FireSIGHT Management Center application could allow unauthenticated, remote attackers to delete a system policy other than their own. The vulnerability is due to improper input validation of certain fields of the HTTP POST request. An attacker could exploit this vulnerability by sending a crafted HTTP POST request with parameters of another system policy that the attacker is not authorized to delete. An exploit could allow the attacker to compromise the integrity of the application by the unexpected removal of a system policy. Availability may also be affected. Cisco has confirmed the vulnerability; however, updates are unavailable. To exploit this vulnerability, an attacker requires authenticated access to the targeted system. Authenticated access may require the attacker to access trusted, internal networks. These requirements could limit the likelihood of a successful exploit.","severity":"Medium","published_at":"2015-08-13T17:38:07Z","updated_at":"2015-08-13T17:38:07Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150813-CVE-2015-4302","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20150813-CVE-2015-4302/csaf/Cisco-SA-20150813-CVE-2015-4302.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.02152},"cves":[{"id":"CVE-2015-4302","kev":false,"epss":{"score":0.02152,"percentile":0.80119,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"}}],"public_evidence":[{"product":{"name":"Cisco Firepower System Software","slug":"cisco-firepower-system-software","vendor":"Cisco"},"cve":{"id":"CVE-2015-4302"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T00:28:20Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Firepower System Software","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.02152,"score_date":"2026-07-19","updated_at":"2026-07-20T05:46:47Z"},"published_at":"2015-08-13T17:38:07Z","updated_at":"2015-08-13T17:38:07Z","advisory_updated_at":"2015-08-13T17:38:07Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150813-CVE-2015-4302","row_display_order":1}]}