Lucene search

K
cveCiscoCVE-2015-6335
HistoryOct 25, 2015 - 2:59 a.m.

CVE-2015-6335

2015-10-2502:59:10
CWE-264
cisco
web.nvd.nist.gov
33
cisco
firesight
management center
cve-2015-6335
policy implementation
cisco vulnerability
remote authenticated administrators
linux commands
root access
cscuw12839

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.4%

The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to bypass intended policy restrictions and execute Linux commands as root via unspecified vectors, aka Bug ID CSCuw12839.

Affected configurations

Nvd
Node
ciscofiresight_system_softwareMatch5.3.1.7
OR
ciscofiresight_system_softwareMatch5.4.0.4
OR
ciscofiresight_system_softwareMatch6.0.0
VendorProductVersionCPE
ciscofiresight_system_software5.3.1.7cpe:2.3:a:cisco:firesight_system_software:5.3.1.7:*:*:*:*:*:*:*
ciscofiresight_system_software5.4.0.4cpe:2.3:a:cisco:firesight_system_software:5.4.0.4:*:*:*:*:*:*:*
ciscofiresight_system_software6.0.0cpe:2.3:a:cisco:firesight_system_software:6.0.0:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

52.4%

Related for CVE-2015-6335