CVE-2015-4224
published 2015-06-26CVE-2015-4224: Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI…
PriorityP337high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.48%
38.9th percentile
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wireless_lan_controller_software | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Wireless LAN Controller Command Injection Vulnerability
vendor_cisco·2015-06-25·CVSS 7.2
CVE-2015-4224 [HIGH] CWE-78 Cisco Wireless LAN Controller Command Injection Vulnerability
Cisco Wireless LAN Controller Command Injection Vulnerability
A vulnerability in the command-line interface (CLI) processor of the Cisco Wireless LAN Controller (WLC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges on the underlying operating system.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted commands through the CLI. An exploit could allow the attacker to read, write, and overwrite any file on the system or execute arbitrary code.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate and have local access to the targeted device
GHSA
GHSA-fwqh-hp5q-r4gh: Cisco Wireless LAN Controller (WLC) devices with software 7
ghsa_unreviewed·2022-05-17
CVE-2015-4224 [HIGH] CWE-78 GHSA-fwqh-hp5q-r4gh: Cisco Wireless LAN Controller (WLC) devices with software 7
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-26
Published