CVE-2015-1322 is a directory traversal vulnerability affecting the network-manager package in specific versions of Ubuntu (vivid, 14.10, and 14.04 LTS). A local attacker can exploit this flaw by using ".." in a filename when requesting modem device contexts, potentially leading to arbitrary file reading or modification of modem configurations. With a CVSS score of 4.6, this vulnerability has a low attack complexity and requires local access, impacting confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
14.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.1:*:*:*:*:*:*:* | ||
<= 0.9.8.7CPE matchmatch criteria | cpe:2.3:a:ubuntu:network-manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.