Lucene search

K
cveCiscoCVE-2015-6370
HistoryNov 19, 2015 - 2:59 a.m.

CVE-2015-6370

2015-11-1902:59:03
CWE-78
cisco
web.nvd.nist.gov
29
cisco
firepower
extensible operating system
os commands
security vulnerability
cliθΎ“ε…₯
bug id
cscux10578

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

5.2%

The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578.

Affected configurations

Nvd
Node
ciscofirepower_extensible_operating_systemMatch1.1\(1.160\)
VendorProductVersionCPE
ciscofirepower_extensible_operating_system1.1(1.160)cpe:2.3:o:cisco:firepower_extensible_operating_system:1.1\(1.160\):*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0

Percentile

5.2%

Related for CVE-2015-6370