Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
2014-11-07T11:55:03.907
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:L/AC:L/Au:S/C:C/I:C/A:C
3.1
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xe | ≤ 3.5e | Yes |
Hardware | cisco | air-ct5760 | * | Yes |
Hardware | cisco | ws-c3850 | * | Yes |
Hardware | cisco | ws-c3860 | * | Yes |