First published: Fri Jul 03 2015(Updated: )
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco NX-OS | =7.2\(0\)zz\(99.3\) | |
Cisco Nexus 93120TX Firmware | ||
Cisco Nexus 93128 Firmware | ||
Cisco Nexus 9332PQ Firmware | ||
Cisco Nexus N9336PQ-X | ||
Cisco Nexus 9372PX-E | ||
Cisco Nexus 9372TX | ||
Cisco Nexus 9396PX Firmware | ||
Cisco Nexus 9396TX Firmware | ||
Cisco Nexus 9504 firmware | ||
Cisco Nexus 9508 | ||
Cisco Nexus 9516 firmware | ||
Cisco NX-OS | =7.2\(0\)zz\(99.1\) | |
Cisco Nexus 3016Q Firmware | ||
Cisco Nexus 3048 Firmware | ||
Cisco Nexus 3064 Firmware | ||
Cisco Nexus 3132Q-XL | ||
Cisco Nexus 3164Q Firmware | ||
Cisco Nexus 3172 Firmware | ||
Cisco Nexus 3232C | ||
Cisco Nexus 3524-xl | ||
Cisco Nexus 3548-X/XL Firmware | ||
Cisco NX-OS | =6.2\(11b\) | |
Cisco MDS 9100 | ||
Cisco MDS 9140 | ||
Cisco MDS 9500 | ||
Cisco MDS 9700 | ||
Cisco NX-OS | =9.1\(1\)sv1\(3.1.8\) | |
Cisco Nexus 1000V for Hyper-V | ||
Cisco Nexus 5548P Firmware | ||
Cisco Nexus 5548UP Firmware | ||
Cisco Nexus 5596T Firmware | ||
Cisco Nexus 5596UP Firmware | ||
Cisco 56128p | ||
Cisco Nexus 5624Q Firmware | ||
Cisco Nexus 5648Q Firmware | ||
Cisco Nexus 5672UP-16G | ||
Cisco Nexus 5696Q Firmware | ||
Cisco NX-OS | =6.2\(12\) | |
Cisco Nexus 7000 | ||
Cisco Nexus 7700 series | ||
Cisco NX-OS | =4.1\(2\)e1\(1\) | |
Cisco Nexus 4001i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4237 has been classified as a high severity vulnerability.
To fix CVE-2015-4237, upgrade to the patched versions of Cisco NX-OS that resolve this issue.
CVE-2015-4237 affects specific versions of Cisco NX-OS on Nexus devices, including versions 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8).
CVE-2015-4237 requires local access to the system to exploit, making remote exploitation unlikely.
CVE-2015-4237 is a command injection vulnerability that allows local users to execute arbitrary OS commands.