PT-2015-2236 · Cisco · Cisco Nx-Os+1

Published

2015-06-30

·

Updated

2016-12-28

·

CVE-2015-4232

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cisco NX-OS version 6.2(10)
Description The issue is related to insufficient access control to files in the network operating system, allowing a local attacker to execute arbitrary OS commands by passing special parameters. This is due to insufficient input sanitization of parameters passed to the tar command in the command-line interpreter. An attacker with local access and authentication to the device can leverage this behavior to execute arbitrary commands on the underlying operating system with user privileges.
Recommendations For Cisco NX-OS version 6.2(10), update to a newer version that includes the fix for this issue, as confirmed by Cisco. As a temporary workaround, consider restricting access to the tar command until a patch is available. Additionally, limit local access and authentication to the device to minimize the risk of exploitation.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11582
CVE-2015-4232

Affected Products

Cisco Nx-Os
Cisco Nexus