CVE-2015-6383 describes a vulnerability in Cisco IOS XE 15.4(3)S on ASR 1000 devices where improper software package loading allows local users to bypass license restrictions and gain root privileges through crafted filenames via the CLI. With a CVSS score of 7.2 (High), this vulnerability has a local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.4\(3\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.4\(3\)s:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.