CVE-2015-4235
published 2015-07-24CVE-2015-4235: Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software…
PriorityP347critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.25%
81.0th percentile
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root privileges via unspecified use of the APIC cluster-management configuration feature, aka Bug IDs CSCuu72094 and CSCuv11991.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Application Policy Infrastructure Controller Access Control Vulnerability
vendor_cisco·2015-07-22·CVSS 8.5
CVE-2015-4235 [HIGH] CWE-264 Cisco Application Policy Infrastructure Controller Access Control Vulnerability
Cisco Application Policy Infrastructure Controller Access Control Vulnerability
A vulnerability in the cluster management configuration of the Cisco Application Policy Infrastructure Controller (APIC) and the Cisco Nexus 9000 Series ACI Mode Switch could allow an authenticated, remote attacker to access the APIC as the root user.
The vulnerability is due to improper implementation of access controls in the APIC filesystem. An attacker could exploit this vulnerability by accessing the cluster management configuration of the APIC. An exploit could allow the attacker to gain access to the APIC as the root user and perform root-level commands.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.co
Cisco
Cisco Application Policy Infrastructure Controller Access Control Vulnerability
vendor_cisco
CVE-2015-4235 Cisco Application Policy Infrastructure Controller Access Control Vulnerability
CVE-2015-4235: Cisco Application Policy Infrastructure Controller Access Control Vulnerability
A vulnerability in the cluster management configuration of the Cisco Application Policy Infrastructure Controller (APIC) and the Cisco Nexus 9000 Series ACI Mode Switch could allow an authenticated, remote attacker to access the APIC as the root user. The vulnerability is due to improper implementation of access controls in the APIC filesystem. An attacker could exploit this vulnerability by accessing the cluster management configuration of the APIC. An exploit could allow the attacker to gain access to the APIC as the root user and perform root -level commands. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloud
GHSA
GHSA-vvgq-gww9-5ghc: Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1
ghsa_unreviewed·2022-05-17
CVE-2015-4235 [HIGH] GHSA-vvgq-gww9-5ghc: Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root privileges via unspecified use of the APIC cluster-management configuration feature, aka Bug IDs CSCuu72094 and CSCuv11991.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-24
Published