Lucene search

K
cveCiscoCVE-2015-4231
HistoryJul 03, 2015 - 10:59 a.m.

CVE-2015-4231

2015-07-0310:59:00
CWE-264
cisco
web.nvd.nist.gov
27
cve-2015-4231
python interpreter
cisco nx-os
nexus 7000
access restrictions
vdc
bug id cscur08416
nvd

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%

The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC’s files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.

Affected configurations

Nvd
Node
cisconx-osMatch6.2\(8a\)
AND
cisconexus_7000Match-
OR
cisconexus_7700Match-
VendorProductVersionCPE
cisconx-os6.2(8a)cpe:2.3:o:cisco:nx-os:6.2\(8a\):*:*:*:*:*:*:*
cisconexus_7000-cpe:2.3:h:cisco:nexus_7000:-:*:*:*:*:*:*:*
cisconexus_7700-cpe:2.3:h:cisco:nexus_7700:-:*:*:*:*:*:*:*

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%