CVE-2015-6298
published 2015-11-06CVE-2015-6298: The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before…
PriorityP342critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
1.66%
74.0th percentile
The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges via crafted certificate-generation arguments, aka Bug ID CSCus83445.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | web_security_appliance | — | — |
| cisco | web_security_appliance | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Web Security Appliance Certificate Generation Command Injection Vulnerability
vendor_cisco·2015-11-04·CVSS 9.0
CVE-2015-6298 [CRITICAL] CWE-78 Cisco Web Security Appliance Certificate Generation Command Injection Vulnerability
Cisco Web Security Appliance Certificate Generation Command Injection Vulnerability
A vulnerability in the certificate generation process in the admin web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system with root-level privileges.
The vulnerability is due to the improper validation of parameters passed to the affected system scripts. An attacker could exploit this vulnerability by passing arbitrary commands as arguments to the affected fields of the web interface. An exploit could allow the attacker to run arbitrary commands on the underlying system with root-level privileges.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerabili
Cisco
Cisco Web Security Appliance Certificate Generation Command Injection Vulnerability
vendor_cisco
CVE-2015-6298 Cisco Web Security Appliance Certificate Generation Command Injection Vulnerability
CVE-2015-6298: Cisco Web Security Appliance Certificate Generation Command Injection Vulnerability
A vulnerability in the certificate generation process in the admin web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system with root -level privileges. The vulnerability is due to the improper validation of parameters passed to the affected system scripts. An attacker could exploit this vulnerability by passing arbitrary commands as arguments to the affected fields of the web interface. An exploit could allow the attacker to run arbitrary commands on the underlying system with root -level privileges. Cisco has released software updates that address this vulnerability.
CWE: CWE-78, CWE-78
Bug IDs:
GHSA
GHSA-hrmr-gjhm-hc4x: The admin web interface in Cisco AsyncOS 8
ghsa_unreviewed·2022-05-17
CVE-2015-6298 [HIGH] CWE-78 GHSA-hrmr-gjhm-hc4x: The admin web interface in Cisco AsyncOS 8
The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges via crafted certificate-generation arguments, aka Bug ID CSCus83445.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-06
Published