First published: Fri Jun 26 2015(Updated: )
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Wireless LAN Controller software | =7.0\(240.0\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4224 has a high severity rating due to its potential for arbitrary command execution in privileged contexts.
To fix CVE-2015-4224, upgrade the Cisco Wireless LAN Controller software to a version that is not affected, specifically beyond 7.0(240.0).
CVE-2015-4224 affects local users of Cisco Wireless LAN Controller devices running software version 7.0(240.0).
CVE-2015-4224 is a command injection vulnerability that allows local users to execute arbitrary operating system commands.
The potential impacts of CVE-2015-4224 include unauthorized access and control over the device's operating system, which could lead to data breaches.