CVE-2015-4232
published 2015-07-03CVE-2015-4232: Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID…
PriorityP426medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.41%
33.3th percentile
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus Devices NX-OS Software Command-Line Interpreter Local Privilege Escalation Vulnerability
vendor_cisco·2015-06-30·CVSS 4.6
CVE-2015-4232 [MEDIUM] CWE-264 Cisco Nexus Devices NX-OS Software Command-Line Interpreter Local Privilege Escalation Vulnerability
Cisco Nexus Devices NX-OS Software Command-Line Interpreter Local Privilege Escalation Vulnerability
A local privilege escalation vulnerability in the command-line interpreter of Cisco Nexus devices could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with user privileges.
The vulnerability exists due to insufficient input sanitization of parameters passed to the tar command on the command-line interpreter of an affected device. An attacker could leverage this behavior to execute arbitrary commands on the underlying operating system with the privileges of the user authenticated to the device.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must have local access and
GHSA
GHSA-3hq6-jjwr-fjv7: Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2015-4232 [MEDIUM] GHSA-3hq6-jjwr-fjv7: Cisco NX-OS 6
Cisco NX-OS 6.2(10) on Nexus and MDS 9000 devices allows local users to execute arbitrary OS commands by entering crafted tar parameters in the CLI, aka Bug ID CSCus44856.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-03
Published