CVE-2015-6424
published 2015-12-18CVE-2015-6424: The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain…
PriorityP426high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.38%
30.9th percentile
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| x.org | xorg-server | >= 0 < 2:1.15.1-0ubuntu2.7 | 2:1.15.1-0ubuntu2.7 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv5.0MEDIUM
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Application Policy Infrastructure Controller Insecure Credentials Vulnerability
vendor_cisco·2015-12-16·CVSS 6.8
CVE-2015-6424 [MEDIUM] CWE-255 Cisco Application Policy Infrastructure Controller Insecure Credentials Vulnerability
Cisco Application Policy Infrastructure Controller Insecure Credentials Vulnerability
A vulnerability in the boot process of the Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to access the APIC as the root user.
The vulnerability is due to improper implementation of access controls in the APIC system. An attacker could exploit this vulnerability by accessing the boot manager of the APIC. An exploit could allow the attacker to access the APIC as the root user and perform root-level commands in single-user mode.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/securit
Cisco
Cisco Application Policy Infrastructure Controller Insecure Credentials Vulnerability
vendor_cisco
CVE-2015-6424 Cisco Application Policy Infrastructure Controller Insecure Credentials Vulnerability
CVE-2015-6424: Cisco Application Policy Infrastructure Controller Insecure Credentials Vulnerability
A vulnerability in the boot process of the Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to access the APIC as the root user. The vulnerability is due to improper implementation of access controls in the APIC system. An attacker could exploit this vulnerability by accessing the boot manager of the APIC. An exploit could allow the attacker to access the APIC as the root user and perform root -level commands in single-user mode. Cisco has released software updates that address this vulnerability.
CWE: CWE-255, CWE-255
Bug IDs: CSCuu83985
GHSA
GHSA-xgmj-8cq2-4f7j: The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1
ghsa_unreviewed·2022-05-17
CVE-2015-6424 [HIGH] GHSA-xgmj-8cq2-4f7j: The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.
OSV
xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
osv·2015-02-17·CVSS 5.0
CVE-2015-0255 xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
xorg-server, xorg-server-lts-trusty, xorg-server-lts-utopic vulnerabilities
Olivier Fourdan discovered that the X.Org X server incorrectly handled
XkbSetGeometry requests resulting in an information leak. An attacker able
to connect to an X server, either locally or remotely, could use this issue
to possibly obtain sensitive information. (CVE-2015-0255)
It was discovered that the X.Org X server incorrectly handled certain
trapezoids. An attacker able to connect to an X server, either locally or
remotely, could use this issue to possibly crash the server. This issue
only affected Ubuntu 12.04 LTS. (CVE-2013-6424)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151216-apichttp://www.securityfocus.com/bid/79410http://www.securitytracker.com/id/1034468http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151216-apichttp://www.securityfocus.com/bid/79410http://www.securitytracker.com/id/1034468
2015-12-18
Published