CVE-2015-0658: Input Validation
The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local network, aka Bug ID CSCur14589.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0658?
CVE-2015-0658 has a critical severity, allowing remote attackers to execute arbitrary commands as root.
How do I fix CVE-2015-0658?
To fix CVE-2015-0658, upgrade to the latest patched versions of Cisco NX-OS as indicated in the vendor's security advisory.
Which systems are affected by CVE-2015-0658?
CVE-2015-0658 affects various versions of Cisco NX-OS, including 6.1(2), 6.1(3), 6.1(4), and others listed in the CVE description.
Can CVE-2015-0658 be exploited over the internet?
CVE-2015-0658 is primarily a local network vulnerability that requires an attacker to be on the same local network.
What are the potential impacts of CVE-2015-0658?
The potential impacts of CVE-2015-0658 include unauthorized root access, which can lead to further system compromises.