Vulnerability Description
The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute arbitrary commands via shell metacharacters in a cl-rctl command label.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cumulusnetworks | Cumulus Linux | <= 2.5.3 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2015/Aug/23Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2015/Aug/23Mailing ListThird Party Advisory
FAQ
What is CVE-2015-5699?
CVE-2015-5699 is a vulnerability with a CVSS score of 7.8 (HIGH). The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute arbitrary commands via shell metacharacters in a cl-rctl command label.
How severe is CVE-2015-5699?
CVE-2015-5699 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5699?
Check the references section above for vendor advisories and patch information. Affected products include: Cumulusnetworks Cumulus Linux.