6.9

CVE-2015-4282

Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root privileges by writing to a file, aka Bug ID CSCuv40504.

Data is provided by the National Vulnerability Database (NVD)
CiscoMobility Services Engine Version5.1_base
CiscoMobility Services Engine Version5.2_base
CiscoMobility Services Engine Version6.0_base
CiscoMobility Services Engine Version7.0_base
CiscoMobility Services Engine Version7.4.100.0
CiscoMobility Services Engine Version7.4.110.0
CiscoMobility Services Engine Version7.4.121.0
CiscoMobility Services Engine Version7.4_base
CiscoMobility Services Engine Version7.5.102.101
CiscoMobility Services Engine Version7.6.100.0
CiscoMobility Services Engine Version7.6.120.0
CiscoMobility Services Engine Version7.6.132.0
CiscoMobility Services Engine Version8.0_base
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.28% 0.508
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C