{"api_version":"1","generated_at":"2026-07-23T11:47:58+00:00","cve":"CVE-2015-4234","urls":{"html":"https://cve.report/CVE-2015-4234","api":"https://cve.report/api/cve/CVE-2015-4234.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-4234","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-4234"},"summary":{"title":"CVE-2015-4234","description":"Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.","state":"PUBLISHED","assigner":"cisco","published_at":"2015-07-03 10:59:02","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/75502","name":"http://www.securityfocus.com/bid/75502","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Multiple Cisco Products CVE-2015-4234 Multiple Local Privilege Escalation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=39571","name":"http://tools.cisco.com/security/center/viewAlert.x?alertId=39571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1032765","name":"http://www.securitytracker.com/id/1032765","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Cisco NX-OS Python Scripting Engine Flaws Lets Local Users Gain Root Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-4234","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4234","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"4234","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"nx-os","cpe6":"6.0\\(2\\)","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4234","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"cisco","cpe5":"nx-os","cpe6":"6.2\\(2\\)","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:11:11.758Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"75502","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/75502"},{"name":"20150630 Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO","x_transferred"],"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=39571"},{"name":"1032765","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1032765"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-06-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-12-23T18:57:01.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"name":"75502","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/75502"},{"name":"20150630 Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities","tags":["vendor-advisory","x_refsource_CISCO"],"url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=39571"},{"name":"1032765","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1032765"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","ID":"CVE-2015-4234","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"75502","refsource":"BID","url":"http://www.securityfocus.com/bid/75502"},{"name":"20150630 Cisco Nexus Devices Python Subsystem Local Privilege Escalation Vulnerabilities","refsource":"CISCO","url":"http://tools.cisco.com/security/center/viewAlert.x?alertId=39571"},{"name":"1032765","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1032765"}]}}}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2015-4234","datePublished":"2015-07-03T10:00:00.000Z","dateReserved":"2015-06-04T00:00:00.000Z","dateUpdated":"2024-08-06T06:11:11.758Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-07-03 10:59:02","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:nx-os:6.0\\(2\\):*:*:*:*:*:*:*","matchCriteriaId":"161C5BDB-CD50-40C7-B972-A1B650607338"},{"vulnerable":true,"criteria":"cpe:2.3:o:cisco:nx-os:6.2\\(2\\):*:*:*:*:*:*:*","matchCriteriaId":"2FDE8EF9-47CF-451D-9570-3D369D74D44F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"4234","Ordinal":"1","Title":"CVE-2015-4234","CVE":"CVE-2015-4234","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"4234","Ordinal":"1","NoteData":"Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input to the Python interpreter, aka Bug IDs CSCun02887, CSCur00115, and CSCur00127.","Type":"Description","Title":"CVE-2015-4234"},{"CveYear":"2015","CveId":"4234","Ordinal":"2","NoteData":"2015-07-03","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"4234","Ordinal":"3","NoteData":"2016-12-23","Type":"Other","Title":"Modified"}]}}}