Vulnerability Name: | CVE-2015-6383 (CCN-108370) | ||||||||
Assigned: | 2015-11-30 | ||||||||
Published: | 2015-11-30 | ||||||||
Updated: | 2017-09-14 | ||||||||
Summary: | Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130. | ||||||||
CVSS v3 Severity: | 7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-6383 Source: CISCO Type: Vendor Advisory 20151130 Cisco ASR 1000 Series Root Shell License Bypass Vulnerability Source: CCN Type: Cisco Security Advisory cisco-sa-20151130-iosxe3s Cisco IOS XE 3S Platforms Series root Shell License Bypass Vulnerability Source: BID Type: UNKNOWN 78521 Source: CCN Type: BID-78521 Cisco IOS XE 3S Software CVE-2015-6383 Local Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1034277 Source: SECTRACK Type: UNKNOWN 1034296 Source: XF Type: UNKNOWN cisco-ioxse-cve20156383-unauth-access(108370) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |