// For flags

CVE-2015-4235

 

Severity Score

9.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root privileges via unspecified use of the APIC cluster-management configuration feature, aka Bug IDs CSCuu72094 and CSCuv11991.

Vulnerabilidad en dispositivos Cisco Application Policy Infrastructure Controller (APIC) con software en sus versiones anteriores a la 1.0(3o) y 1.1 anteriores a la 1.1(1j) y dispositivos Nexus 9000 ACI con software en sus versiones anteriores a la 11.0(4o) y 11.1 anteriores a la 11.1(1j), no restringen adecuadamente el acceso al sistema de archivos APIC lo cual permite a usuarios remotos autenticados obtener privilegios de root a través del uso no especificado de la configuración de la funcionalidad cluster-management en el APIC, también conocido como Bug ID CSCuu72094 y CSCuv11991.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-06-04 CVE Reserved
  • 2015-07-24 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Application Policy Infrastructure Controller \(apic\)
Search vendor "Cisco" for product "Application Policy Infrastructure Controller \(apic\)"
1.0\(1e\)
Search vendor "Cisco" for product "Application Policy Infrastructure Controller \(apic\)" and version "1.0\(1e\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(1b\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(1b\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(1c\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(1c\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(1d\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(1d\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(1e\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(1e\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(2j\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(2j\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(2m\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(2m\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(3f\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(3f\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(3i\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(3i\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(3k\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(3k\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(3n\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(3n\)"
-
Affected
Cisco
Search vendor "Cisco"
Nx-os
Search vendor "Cisco" for product "Nx-os"
11.0\(4h\)
Search vendor "Cisco" for product "Nx-os" and version "11.0\(4h\)"
-
Affected