CVE-2015-4244
CVE-2015-4244 is a high-severity vulnerability in Cisco Asr 5000 Series Software with a CVSS 2.0 base score of 7.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: High (CVSS 2.0 base score 7.2)
- EPSS exploit prediction: 0% (37th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-78
- Affected product: Cisco Asr 5000 Series Software
- Published:
- Last modified:
Description
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.
Frequently asked questions
- What is CVE-2015-4244?
- The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.
- How severe is CVE-2015-4244?
- CVE-2015-4244 has a CVSS 2.0 base score of 7.2, rated high severity.
- Is CVE-2015-4244 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (37th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2015-4244?
- CVE-2015-4244 affects Cisco Asr 5000 Series Software. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2015-4244?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2015-4244 published?
- CVE-2015-4244 was published on 2015-07-10 and last updated on 2026-06-17.
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39677
- http://www.securitytracker.com/id/1032839
Affected products (1)
- cpe:2.3:a:cisco:asr_5000_series_software:14.0:*:*:*:*:*:*:*
More vulnerabilities in Cisco Asr 5000 Series Software
- CVE-2017-3819 — High (CVSS 8.8): A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR…
- CVE-2017-6612 — High (CVSS 8.6): A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers…
- CVE-2017-6672 — High (CVSS 7.5): A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation…
- CVE-2016-9203 — High (CVSS 7.5): A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco ASR 5000 Series Software could allow an…
- CVE-2016-6467 — High (CVSS 7.5): A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series…
- CVE-2016-6466 — High (CVSS 7.5): A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated,…
All CVEs affecting Cisco Asr 5000 Series Software →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-100382 — Critical (CVSS 10.0): Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia…
- CVE-2026-77521 — Critical (CVSS 10.0): MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool,…
- CVE-2026-82004 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76197 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76195 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…