Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2014-11-07T11:00:00
Updated: 2017-09-07T15:57:01
Reserved: 2014-10-08T00:00:00
Link: CVE-2014-7990
JSON object: View
NVD Information
Status : Modified
Published: 2014-11-07T11:55:03.907
Modified: 2017-09-08T01:29:19.013
Link: CVE-2014-7990
JSON object: View
Redhat Information
No data.
CWE