First published: Fri Jul 03 2015(Updated: )
The Python interpreter in Cisco NX-OS 6.2(8a) on Nexus 7000 devices allows local users to bypass intended access restrictions and delete an arbitrary VDC's files by leveraging administrative privileges in one VDC, aka Bug ID CSCur08416.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =6.2\(8a\) | |
Cisco Nexus 7000 | ||
Cisco Nexus 7700 series |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4231 is considered a critical vulnerability due to the potential for administrative privilege escalation and unauthorized file deletion.
To fix CVE-2015-4231, it is recommended to upgrade to a fixed version of Cisco NX-OS that addresses this vulnerability.
CVE-2015-4231 affects local users with administrative privileges on Cisco NX-OS 6.2(8a) systems running on Nexus 7000 devices.
Attackers exploiting CVE-2015-4231 can bypass access restrictions and delete important files from an arbitrary Virtual Device Context (VDC).
CVE-2015-4231 was disclosed in 2015, highlighting a significant security risk in Cisco NX-OS.