CVE-2015-6375
published 2015-11-21CVE-2015-6375: The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.31%
23.6th percentile
The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | networking_services_sensitive | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Networking Services Sensitive Information Disclosure Vulnerability
vendor_cisco·2015-11-20·CVSS 4.0
CVE-2015-6375 [MEDIUM] CWE-200 Cisco Networking Services Sensitive Information Disclosure Vulnerability
Cisco Networking Services Sensitive Information Disclosure Vulnerability
A vulnerability in the debug logging function of Cisco Networking Services (CNS) used for configuring Cisco IOS networking devices could allow an authenticated, local attacker to disclose sensitive data.
The vulnerability is due to insufficient protections of sensitive data at rest. An attacker could exploit this vulnerability by accessing a specific file and reading the sensitive information.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151120-ns
Cisco
Cisco Networking Services Sensitive Information Disclosure Vulnerability
vendor_cisco
CVE-2015-6375 Cisco Networking Services Sensitive Information Disclosure Vulnerability
CVE-2015-6375: Cisco Networking Services Sensitive Information Disclosure Vulnerability
A vulnerability in the debug logging function of Cisco Networking Services (CNS) used for configuring Cisco IOS networking devices could allow an authenticated, local attacker to disclose sensitive data. The vulnerability is due to insufficient protections of sensitive data at rest. An attacker could exploit this vulnerability by accessing a specific file and reading the sensitive information. Cisco has not released software updates that address this vulnerability.
CWE: CWE-200, CWE-200
Bug IDs: CSCux18010
GHSA
GHSA-cm3x-f29c-r8jp: The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-6375 [LOW] CWE-200 GHSA-cm3x-f29c-r8jp: The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15
The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-11-21
Published