HIGH · 7.2

CVE-2015-4244

The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these comman...

Vulnerability Description

The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoAsr 5000 Series Software14.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-4244?

CVE-2015-4244 is a vulnerability with a CVSS score of 7.2 (HIGH). The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these comman...

How severe is CVE-2015-4244?

CVE-2015-4244 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-4244?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Asr 5000 Series Software.