Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-4237


The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.


Published

2015-07-03T10:59:03.060

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-78
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco nx-os 7.2\(0\)zz\(99.3\) Yes
Hardware cisco nexus_93120tx - No
Hardware cisco nexus_93128tx - No
Hardware cisco nexus_9332pq - No
Hardware cisco nexus_9336pq_aci_spine - No
Hardware cisco nexus_9372px - No
Hardware cisco nexus_9372tx - No
Hardware cisco nexus_9396px - No
Hardware cisco nexus_9396tx - No
Hardware cisco nexus_9504 - No
Hardware cisco nexus_9508 - No
Hardware cisco nexus_9516 - No
Operating System cisco nx-os 7.2\(0\)zz\(99.1\) Yes
Hardware cisco nexus_3016 - No
Hardware cisco nexus_3048 - No
Hardware cisco nexus_3064 - No
Hardware cisco nexus_3132q - No
Hardware cisco nexus_3164q - No
Hardware cisco nexus_3172 - No
Hardware cisco nexus_3232c - No
Hardware cisco nexus_3524 - No
Hardware cisco nexus_3548 - No
Operating System cisco nx-os 6.2\(11b\) Yes
Hardware cisco mds_9100 - No
Hardware cisco mds_9140 * No
Hardware cisco mds_9500 - No
Hardware cisco mds_9700 - No
Operating System cisco nx-os 9.1\(1\)sv1\(3.1.8\) Yes
Hardware cisco nexus_1000v - No
Operating System cisco nx-os 7.2\(0\)zz\(99.1\) Yes
Hardware cisco nexus_5548p - No
Hardware cisco nexus_5548up - No
Hardware cisco nexus_5596t - No
Hardware cisco nexus_5596up - No
Hardware cisco nexus_56128p - No
Hardware cisco nexus_5624q - No
Hardware cisco nexus_5648q - No
Hardware cisco nexus_5672up - No
Hardware cisco nexus_5696q - No
Operating System cisco nx-os 6.2\(12\) Yes
Hardware cisco nexus_7000 - No
Hardware cisco nexus_7700 - No
Operating System cisco nx-os 4.1\(2\)e1\(1\) Yes
Hardware cisco nexus_4001i - No

References