CVE-2015-4234
published 2015-07-03CVE-2015-4234: Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.42%
34.2th percentile
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h28w-hpqp-8qrm: Cisco NX-OS 6
ghsa_unreviewed·2022-05-17
CVE-2015-4234 [HIGH] GHSA-h28w-hpqp-8qrm: Cisco NX-OS 6
Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.
Cisco
Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities
vendor_cisco·2015-06-30·CVSS 7.2
CVE-2015-4234 [HIGH] CWE-264 Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities
Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities
Multiple privilege escalation vulnerabilities in the Python subsystem of Cisco Nexus devices running Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privileges.
The vulnerabilities are due to insufficient hardening of the operating system on which NX-OS is based. An attacker who has sufficient privileges to execute arbitrary Python scripts on an affected device could use this access to obtain root privileges.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit these vulnerabilities, an attacker must have local access and authenticate to the targeted device. These requirements could limit the possibility of a successful exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-03
Published