CVE-2015-0693
published 2015-04-15CVE-2015-0693: Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status…
PriorityP434high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.38%
30.4th percentile
Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via a crafted pickle file, aka Bug ID CSCut39259.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Web Security Appliance Python File Processing Privilege Escalation Vulnerability
vendor_cisco·2015-04-13·CVSS 7.2
CVE-2015-0693 [HIGH] CWE-20 Cisco Web Security Appliance Python File Processing Privilege Escalation Vulnerability
Cisco Web Security Appliance Python File Processing Privilege Escalation Vulnerability
A vulnerability in the status-checking process of remote access tunnels for supporting Cisco Web Security Appliances (WSA) could allow an authenticated, local attacker to execute arbitrary Python code on the affected system.
The vulnerability is due to improper usage and handling of the pickle Python module by the affected software. An attacker could exploit this vulnerability by submitting a crafted pickle file to an affected device. A successful exploit could be used to conduct further attacks.
Cisco has confirmed the vulnerability; however, no software updates are available.
To exploit the vulnerability, the attacker must log in locally to the vulnerable device. The access requirement reduces the
GHSA
GHSA-xhwq-qc65-7mcj: Cisco Web Security Appliance (WSA) devices with software 8
ghsa_unreviewed·2022-05-17
CVE-2015-0693 [HIGH] CWE-20 GHSA-xhwq-qc65-7mcj: Cisco Web Security Appliance (WSA) devices with software 8
Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via a crafted pickle file, aka Bug ID CSCut39259.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-15
Published