Lucene search

K
cveCiscoCVE-2015-0693
HistoryApr 15, 2015 - 10:59 a.m.

CVE-2015-0693

2015-04-1510:59:01
CWE-20
cisco
web.nvd.nist.gov
31
cve-2015-0693
cisco web security appliance
wsa
python code execution
privilege escalation
nvd
bug id cscut39259

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0

Percentile

5.1%

Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via a crafted pickle file, aka Bug ID CSCut39259.

Affected configurations

Nvd
Node
ciscoweb_security_applianceMatch8.5_base
VendorProductVersionCPE
ciscoweb_security_appliance8.5_basecpe:2.3:a:cisco:web_security_appliance:8.5_base:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2015-0693