First published: Fri Nov 06 2015(Updated: )
Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root privileges by writing to a file, aka Bug ID CSCuv40504.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Mobility Services Engine | =5.1_base | |
Cisco Mobility Services Engine | =5.2_base | |
Cisco Mobility Services Engine | =6.0_base | |
Cisco Mobility Services Engine | =7.0_base | |
Cisco Mobility Services Engine | =7.4.100.0 | |
Cisco Mobility Services Engine | =7.4.110.0 | |
Cisco Mobility Services Engine | =7.4.121.0 | |
Cisco Mobility Services Engine | =7.4_base | |
Cisco Mobility Services Engine | =7.5.102.101 | |
Cisco Mobility Services Engine | =7.6.100.0 | |
Cisco Mobility Services Engine | =7.6.120.0 | |
Cisco Mobility Services Engine | =7.6.132.0 | |
Cisco Mobility Services Engine | =8.0\(110.0\) | |
Cisco Mobility Services Engine | =8.0_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-4282 is considered critical due to the potential for local users to obtain root privileges.
To fix CVE-2015-4282, upgrade to a patched version of Cisco Mobility Services Engine as recommended by Cisco.
CVE-2015-4282 affects Cisco Mobility Services Engine versions up to 8.0.120.7.
CVE-2015-4282 is a privilege escalation vulnerability that exploits weak file permissions.
Local users on systems running affected versions of Cisco Mobility Services Engine can be impacted by CVE-2015-4282.