CVE-2015-4244
published 2015-07-10CVE-2015-4244: The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging…
PriorityP336high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.44%
35.8th percentile
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_software | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASR 5000 Series Software Local Command Injection Vulnerability
vendor_cisco·2015-07-09·CVSS 7.2
CVE-2015-4244 [HIGH] CWE-78 Cisco ASR 5000 Series Software Local Command Injection Vulnerability
Cisco ASR 5000 Series Software Local Command Injection Vulnerability
A vulnerability in the boot process of the Cisco ASR5000 and ASR5500 (ASK5K) System Software could allow an authenticated, local attacker to cause commands to be executed during the boot process.
The vulnerability is due to improper reading of a local file on Compact Flash (CF) during the boot process. An attacker could exploit this vulnerability by logging in as an administrator-privileged user and writing a file to CF with a set of Linux commands. An exploit could allow the attacker to execute this list of unexpected Linux commands at boot time. The commands are contained in the file that was written out by the malicious administrative user.
Cisco has confirmed the vulnerability and released software updates.
To ex
GHSA
GHSA-hg76-79w5-rcwg: The boot implementation on Cisco ASR 5000 and 5500 devices with software 14
ghsa_unreviewed·2022-05-17
CVE-2015-4244 [HIGH] CWE-78 GHSA-hg76-79w5-rcwg: The boot implementation on Cisco ASR 5000 and 5500 devices with software 14
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-10
Published