VulnerabilityModified
CVE-2015-6265
The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug…
MEDIUM 4.3EPSS 1.84%
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug ID CSCur23662.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/application control engine 4700
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=40666Vendor Advisory
- http://www.securityfocus.com/bid/76491Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033381Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=40666Vendor Advisory
- http://www.securityfocus.com/bid/76491Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1033381Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.