CVE-2015-6375: Infoleak
Published Nov 21, 2015
·Updated
The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010.
Affected Software
1 affected component
Cisco IOS=15.2\(2\)e3
Event History
Nov 21, 2015
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6375?
CVE-2015-6375 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-6375?
To mitigate CVE-2015-6375, update your Cisco IOS to a patched version that resolves this vulnerability.
3
What type of information can be exposed due to CVE-2015-6375?
CVE-2015-6375 allows local users to access sensitive information from an unspecified file.
4
Which versions of Cisco IOS are affected by CVE-2015-6375?
CVE-2015-6375 specifically affects Cisco IOS version 15.2(2)E3.
5
Is it possible to exploit CVE-2015-6375 remotely?
No, CVE-2015-6375 requires local access to exploit the vulnerability.