PT-2015-2237 · Python+1 · Python+1

Published

2015-07-03

·

Updated

2016-12-28

·

CVE-2015-4234

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco NX-OS versions 6.0(2) through 6.2(2)
Description The issue is related to an improper OS configuration in Cisco NX-OS, which allows local users to obtain root access via unspecified input to the Python interpreter. This is due to inadequate access restrictions to certain functions. An attacker, acting locally, can exploit this issue by providing a specific set of commands to the Python interpreter, potentially gaining root user privileges.
Recommendations For Cisco NX-OS versions 6.0(2) through 6.2(2), consider restricting access to the Python interpreter until a proper configuration or patch is available. As a temporary workaround, limit the use of the Python interpreter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11583
CVE-2015-4234

Affected Products

Cisco Nx-Os
Python