Vulnerability Name: | CVE-2015-4234 (CCN-104314) | ||||||||
Assigned: | 2015-06-30 | ||||||||
Published: | 2015-06-30 | ||||||||
Updated: | 2016-12-28 | ||||||||
Summary: | Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127. | ||||||||
CVSS v3 Severity: | 8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-4234 Source: CCN Type: Cisco Vulnerability Alert 39571 Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities Source: CISCO Type: Vendor Advisory 20150630 Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 75502 Source: SECTRACK Type: Third Party Advisory, VDB Entry 1032765 Source: XF Type: UNKNOWN cisco-nexus-cve20154234-priv-esc(104314) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |