The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Mds 9100
Subscribe
Mds 9140
Subscribe
Mds 9500
Subscribe
Mds 9700
Subscribe
Nexus 1000v
Subscribe
Nexus 3016
Subscribe
Nexus 3048
Subscribe
Nexus 3064
Subscribe
Nexus 3132q
Subscribe
Nexus 3164q
Subscribe
Nexus 3172
Subscribe
Nexus 3232c
Subscribe
Nexus 3524
Subscribe
Nexus 3548
Subscribe
Nexus 4001i
Subscribe
Nexus 5548p
Subscribe
Nexus 5548up
Subscribe
Nexus 5596t
Subscribe
Nexus 5596up
Subscribe
Nexus 56128p
Subscribe
Nexus 5624q
Subscribe
Nexus 5648q
Subscribe
Nexus 5672up
Subscribe
Nexus 5696q
Subscribe
Nexus 7000
Subscribe
Nexus 7700
Subscribe
Nexus 93120tx
Subscribe
Nexus 93128tx
Subscribe
Nexus 9332pq
Subscribe
Nexus 9336pq Aci Spine
Subscribe
Nexus 9372px
Subscribe
Nexus 9372tx
Subscribe
Nexus 9396px
Subscribe
Nexus 9396tx
Subscribe
Nexus 9504
Subscribe
Nexus 9508
Subscribe
Nexus 9516
Subscribe
Nx-os
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-4260 | The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-06T06:11:12.442Z
Reserved: 2015-06-04T00:00:00.000Z
Link: CVE-2015-4237
No data.
Status : Deferred
Published: 2015-07-03T10:59:03.060
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-4237
No data.
OpenCVE Enrichment
No data.
EUVD