6.9
CVSSv2

CVE-2015-4282

Published: 06/11/2015 Updated: 06/01/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cisco Mobility Services Engine (MSE) up to and including 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root privileges by writing to a file, aka Bug ID CSCuv40504.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco mobility services engine 5.1_base

cisco mobility services engine 8.0\\(110.0\\)

cisco mobility services engine 7.4.100.0

cisco mobility services engine 7.4.110.0

cisco mobility services engine 7.4.121.0

cisco mobility services engine 7.5.102.101

cisco mobility services engine 6.0_base

cisco mobility services engine 7.4_base

cisco mobility services engine 7.6.100.0

cisco mobility services engine 7.6.132.0

cisco mobility services engine 5.2_base

cisco mobility services engine 7.0_base

cisco mobility services engine 7.6.120.0

cisco mobility services engine 8.0_base

Vendor Advisories

A vulnerability in the installation procedure of the Cisco Mobility Services Engine (MSE) appliance could allow an authenticated, local attacker to escalate to the root level The vulnerability is due to incorrect installation and permissions settings on binary files during the MSE physical or virtual appliance install procedure An attacker could ...