7.8
CVSSv3

CVE-2015-5699

Published: 22/10/2017 Updated: 14/11/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and previous versions allows local users to execute arbitrary commands via shell metacharacters in a cl-rctl command label.

Vulnerable Product Search on Vulmon Subscribe to Product

cumulusnetworks cumulus linux

Exploits

Cumulus Linux's Switch Configuration Tools Backend, clcmd_server, is vulnerable to local privilege escalation via command injection Cumulus Linux's clcmd_server, when receiving commands that end in user supplied labels, will execute any other command appended to the end of it whether it is in the Rosetta or not And it will do so using its own run ...