CVE-2015-6383Cisco IOS XE vulnerability

CWE-2644 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 74.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 3
Latest updateMay 17

Description

Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

NVDcisco/ios_xe15.4\(3\)s

🔴Vulnerability Details

2
GHSA
GHSA-fmwc-8v8w-36mr: Cisco IOS XE 152022-05-17
CVEList
CVE-2015-6383: Cisco IOS XE 152015-12-03

📋Vendor Advisories

1
Cisco
Cisco IOS XE 3S Platforms Series root Shell License Bypass Vulnerability2015-11-30
CVE-2015-6383 — Cisco IOS XE vulnerability | cvebase