// For flags

CVE-2015-4282

 

Severity Score

6.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root privileges by writing to a file, aka Bug ID CSCuv40504.

Cisco Mobility Services Engine (MSE) hasta la versión 8.0.120.7 utiliza permisos débiles para archivos binarios no especificados, lo que permite a usuarios locales obtener privilegios root escribiendo en un archivo, también conocido como Bug ID CSCuv40504

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-06-04 CVE Reserved
  • 2015-11-06 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
5.1_base
Search vendor "Cisco" for product "Mobility Services Engine" and version "5.1_base"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
5.2_base
Search vendor "Cisco" for product "Mobility Services Engine" and version "5.2_base"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
6.0_base
Search vendor "Cisco" for product "Mobility Services Engine" and version "6.0_base"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.0_base
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.0_base"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.4.100.0
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.4.100.0"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.4.110.0
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.4.110.0"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.4.121.0
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.4.121.0"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.4_base
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.4_base"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.5.102.101
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.5.102.101"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.6.100.0
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.6.100.0"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.6.120.0
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.6.120.0"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
7.6.132.0
Search vendor "Cisco" for product "Mobility Services Engine" and version "7.6.132.0"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
8.0\(110.0\)
Search vendor "Cisco" for product "Mobility Services Engine" and version "8.0\(110.0\)"
-
Affected
Cisco
Search vendor "Cisco"
Mobility Services Engine
Search vendor "Cisco" for product "Mobility Services Engine"
8.0_base
Search vendor "Cisco" for product "Mobility Services Engine" and version "8.0_base"
-
Affected