CVE Vulnerabilities

CVE-2015-0692

Published: Apr 11, 2015 | Modified: Jan 06, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel-status checks, which allows local users to execute arbitrary Python code and gain privileges via crafted serialized objects, aka Bug ID CSCut39230.

Affected Software

Name Vendor Start Version End Version
Web_security_appliance Cisco 8.5_base (including) 8.5_base (including)

References