CVE-2015-4231
published 2015-07-03CVE-2015-4231: The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's…
PriorityP417low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.39%
31.6th percentile
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
vendor_cisco3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus 7000 Devices Virtual Device Context Privilege Escalation Vulnerability
vendor_cisco·2015-06-30·CVSS 3.6
CVE-2015-4231 [LOW] CWE-264 Cisco Nexus 7000 Devices Virtual Device Context Privilege Escalation Vulnerability
Cisco Nexus 7000 Devices Virtual Device Context Privilege Escalation Vulnerability
A privilege escalation vulnerability in the Python scripting subsystem of Cisco Nexus 7000 devices that have been configured with multiple virtual device contexts (VDCs) could allow an authenticated, local attacker to delete files owned by a different VDC on the device.
The vulnerability exists due to incomplete privilege separation of the Python scripting engine across multiple VDCs. An attacker with administrative privileges in a specific VDC could exploit this vulnerability to remove files owned by a separate VDC. This could result in a denial of service (DoS) condition on the affected device.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerab
GHSA
GHSA-pmh9-frrx-c2qm: The Python interpreter in Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2015-4231 [LOW] GHSA-pmh9-frrx-c2qm: The Python interpreter in Cisco NX-OS 6
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-03
Published