Vulnerability Name: | CVE-2015-4244 (CCN-104509) | ||||||||
Assigned: | 2015-07-09 | ||||||||
Published: | 2015-07-09 | ||||||||
Updated: | 2016-12-29 | ||||||||
Summary: | The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278. | ||||||||
CVSS v3 Severity: | 8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-78 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-4244 Source: CCN Type: Cisco Vulnerability Alert 39677 Cisco ASR 5000 Series Software Local Command Injection Vulnerability Source: CISCO Type: Vendor Advisory 20150709 Cisco ASR 5000 Series Software Local Command Injection Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1032839 Source: XF Type: UNKNOWN cisco-asr-cve20154244-command-exec(104509) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |