CVE Vulnerabilities

CVE-2015-4282

Published: Nov 06, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root privileges by writing to a file, aka Bug ID CSCuv40504.

Affected Software

NameVendorStart VersionEnd Version
Mobility_services_engineCisco5.1_base (including)5.1_base (including)
Mobility_services_engineCisco5.2_base (including)5.2_base (including)
Mobility_services_engineCisco6.0_base (including)6.0_base (including)
Mobility_services_engineCisco7.0_base (including)7.0_base (including)
Mobility_services_engineCisco7.4.100.0 (including)7.4.100.0 (including)
Mobility_services_engineCisco7.4.110.0 (including)7.4.110.0 (including)
Mobility_services_engineCisco7.4.121.0 (including)7.4.121.0 (including)
Mobility_services_engineCisco7.4_base (including)7.4_base (including)
Mobility_services_engineCisco7.5.102.101 (including)7.5.102.101 (including)
Mobility_services_engineCisco7.6.100.0 (including)7.6.100.0 (including)
Mobility_services_engineCisco7.6.120.0 (including)7.6.120.0 (including)
Mobility_services_engineCisco7.6.132.0 (including)7.6.132.0 (including)
Mobility_services_engineCisco8.0(110.0) (including)8.0(110.0) (including)
Mobility_services_engineCisco8.0_base (including)8.0_base (including)

References