PT-2015-7213 · Cisco · Cisco Ios Xe
Published
2015-11-30
·
Updated
2017-09-14
·
CVE-2015-6383
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE versions 15.4(3)S and 3S
Description
A local user can bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames. The vulnerability occurs because parameters to diagnostic commands at the command-line interface (CLI) are not properly validated. An attacker could exploit this by authenticating to the affected device at privileged level 15 and providing crafted parameters to the diagnostic commands, potentially allowing further compromise.
Recommendations
For Cisco IOS XE version 15.4(3)S, update to a version that includes the fix for this issue.
For Cisco IOS XE version 3S, apply the software updates released by Cisco that address this vulnerability.
As a temporary workaround, consider restricting access to the diagnostic commands at the CLI to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe