Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: cisco

Published: 2014-11-07T11:00:00

Updated: 2017-09-07T15:57:01

Reserved: 2014-10-08T00:00:00


Link: CVE-2014-7990

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2014-11-07T11:55:03.907

Modified: 2017-09-08T01:29:19.013


Link: CVE-2014-7990

JSON object: View

cve-icon Redhat Information

No data.

CWE