CVE-2015-6315
published 2015-10-13CVE-2015-6315: Cisco Aironet 1850 access points with software 8.1(112.4) allow local users to gain privileges via crafted CLI commands, aka Bug ID CSCuv79694.
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.38%
30.3th percentile
Cisco Aironet 1850 access points with software 8.1(112.4) allow local users to gain privileges via crafted CLI commands, aka Bug ID CSCuv79694.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_1850_access_point | — | — |
| cisco | aironet_access_point_software | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9pqm-mqmp-pv7f: Cisco Aironet 1850 access points with software 8
ghsa_unreviewed·2022-05-17
CVE-2015-6315 [HIGH] GHSA-9pqm-mqmp-pv7f: Cisco Aironet 1850 access points with software 8
Cisco Aironet 1850 access points with software 8.1(112.4) allow local users to gain privileges via crafted CLI commands, aka Bug ID CSCuv79694.
Cisco
Cisco Aironet 1850 Access Point Privilege Escalation Vulnerability
vendor_cisco·2015-10-05·CVSS 6.8
CVE-2015-6315 [MEDIUM] CWE-264 Cisco Aironet 1850 Access Point Privilege Escalation Vulnerability
Cisco Aironet 1850 Access Point Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of the Cisco Aironet 1850 Series Access Point device could allow an authenticated, local attacker to obtain elevated privileges to the restricted shell on the device.
The vulnerability is due to a lack of proper escape protections when validating CLI commands entered at the device prompt. An authenticated attacker could exploit this vulnerability by entering malicious commands at the CLI to obtain access to the restricted shell. An exploit could allow the attacker to obtain root-level privileges on the affected device.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is ava
Cisco
Cisco Aironet 1850 Access Point Privilege Escalation Vulnerability
vendor_cisco
CVE-2015-6315 Cisco Aironet 1850 Access Point Privilege Escalation Vulnerability
CVE-2015-6315: Cisco Aironet 1850 Access Point Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of the Cisco Aironet 1850 Series Access Point device could allow an authenticated, local attacker to obtain elevated privileges to the restricted shell on the device. The vulnerability is due to a lack of proper escape protections when validating CLI commands entered at the device prompt. An authenticated attacker could exploit this vulnerability by entering malicious commands at the CLI to obtain access to the restricted shell. An exploit could allow the attacker to obtain root -level privileges on the affected device. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCuv79694
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-13
Published