Vulnerability Description
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Asr 5000 Series Software | 14.0 |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39677Vendor Advisory
- http://www.securitytracker.com/id/1032839Third Party AdvisoryVDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39677Vendor Advisory
- http://www.securitytracker.com/id/1032839Third Party AdvisoryVDB Entry
FAQ
What is CVE-2015-4244?
CVE-2015-4244 is a vulnerability with a CVSS score of 7.2 (HIGH). The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these comman...
How severe is CVE-2015-4244?
CVE-2015-4244 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-4244?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Asr 5000 Series Software.