CVE-2015-4237
published 2015-07-03CVE-2015-4237: The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to…
PriorityP426medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.44%
35.8th percentile
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
| cisco | nx-os | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Nexus Operating System Devices Command Line Interface Local Privilege Escalation Vulnerability
vendor_cisco·2015-07-01·CVSS 4.6
CVE-2015-4237 [MEDIUM] CWE-264 Cisco Nexus Operating System Devices Command Line Interface Local Privilege Escalation Vulnerability
Cisco Nexus Operating System Devices Command Line Interface Local Privilege Escalation Vulnerability
A vulnerability in the Command Line Interface (CLI) parser of Cisco Nexus Operating System (NX-OS) devices could allow an authenticated, local attacker to perform a privilege escalation.
The vulnerability is due to improper input validation of special characters within filenames. An attacker could exploit this vulnerability by authenticating at the local shell and writing a file to disk with certain special characters. The attacker could then use that file with other CLI commands to obtain a shell prompt at their current privilege level. An exploit could allow the attacker to read and write files and perform other privileged commands.
Cisco has confirmed the vulnerability; however, softw
GHSA
GHSA-p7qf-fqjr-3jrq: The CLI parser in Cisco NX-OS 4
ghsa_unreviewed·2022-05-17
CVE-2015-4237 [MEDIUM] CWE-78 GHSA-p7qf-fqjr-3jrq: The CLI parser in Cisco NX-OS 4
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-03
Published