CVE-2015-4186
Last modified
CVE-2015-4186 is a vulnerability of currently unknown severity. The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a crafted option value, aka Bug ID CSCug54412.. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a crafted option value, aka Bug ID CSCug54412.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Virtualization Experience Client 6000 Series Firmware | 11.2\(27.4\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4186?
How severe is CVE-2015-4186?
How do I fix CVE-2015-4186?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-4180Directory traversal vulnerability in get_file.php in phpMyBa…
- CVE-2015-4181Directory traversal vulnerability in get_file.php in phpMyBa…
- CVE-2015-4182The administrative web interface in Cisco Identity Services …
- CVE-2015-4183Cisco UCS Central Software 1.2(1a) allows local users to gai…
- CVE-2015-4184The anti-spam scanner on Cisco Email Security Appliance (ESA…
- CVE-2015-4185The TCL interpreter in Cisco IOS 15.2 does not properly main…
- CVE-2015-4188SQL injection vulnerability in the Manager interface in Cisc…
- CVE-2015-4189Cross-site request forgery (CSRF) vulnerability in Cisco Dat…
- CVE-2015-4190Cisco Cloud Portal in Cisco Prime Service Catalog 9.4.1_vort…
- CVE-2015-4191Cisco IOS XR 5.2.1 allows remote attackers to cause a denial…
- CVE-2015-4194The web-based administrative interface in Cisco WebEx Meetin…
- CVE-2015-4195Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users t…
Are you affected by CVE-2015-4186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
