CVE-2015-4235
Estado: ModificadaAlta (9)—
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root privileges via unspecified use of the APIC cluster-management configuration feature, aka Bug IDs CSCuu72094 and CSCuv11991.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
- Puntuación base: 9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.25%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-264
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-4235",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "psirt@cisco.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-07-24T14:59:00.073",
"references": [
{
"url": "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic",
"tags": [
"Vendor Advisory"
],
"source": "psirt@cisco.com"
},
{
"url": "http://www.securitytracker.com/id/1033025",
"source": "psirt@cisco.com"
},
{
"url": "http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1033025",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root privileges via unspecified use of the APIC cluster-management configuration feature, aka Bug IDs CSCuu72094 and CSCuv11991."
},
{
"lang": "es",
"value": "Vulnerabilidad en dispositivos Cisco Application Policy Infrastructure Controller (APIC) con software en sus versiones anteriores a la 1.0(3o) y 1.1 anteriores a la 1.1(1j) y dispositivos Nexus 9000 ACI con software en sus versiones anteriores a la 11.0(4o) y 11.1 anteriores a la 11.1(1j), no restringen adecuadamente el acceso al sistema de archivos APIC lo cual permite a usuarios remotos autenticados obtener privilegios de root a través del uso no especificado de la configuración de la funcionalidad cluster-management en el APIC, también conocido como Bug ID CSCuu72094 y CSCuv11991."
}
],
"lastModified": "2026-06-17T00:26:58.390",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:cisco:application_policy_infrastructure_controller_\\(apic\\):1.0\\(1e\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59595A27-AAA7-4659-BAE7-8A0FE8613CB5"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(1b\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C64CC640-B37D-4064-8946-B8CCCDE1A6EF"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(1c\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E8983275-20C6-487E-A265-3836F06AB226"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(1d\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CBCA0A4F-D475-405C-B9A7-EBB0A816B9C5"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(1e\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA0E0039-23E1-425B-8B2C-DFE2C185CC8B"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(2j\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C3FB2AC-934D-4F12-9E9B-EA5F0731DA4D"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(2m\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BACE91F5-EC9B-4486-80F1-CFC3DA570B9B"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(3f\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C60E5B9-10AB-4A69-B28D-0D526756E6B6"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(3i\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "979FEE23-2C28-4212-9DA5-10A0EAFE1668"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(3k\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B610400-181F-4621-B27B-18C2609990DB"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(3n\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4585B70C-E162-42FA-9CB8-42C1F34017AB"
},
{
"criteria": "cpe:2.3:o:cisco:nx-os:11.0\\(4h\\):*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "788E6471-F000-45A7-9829-71F7AE5ED1B7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@cisco.com"
}