CVE-2015-6385 describes a privilege escalation vulnerability in the publish-event event-manager feature of Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices. This flaw allows local administrative users to execute arbitrary commands with root privileges by manipulating environment variables. With a CVSS score of 7.2, it is considered high severity due to its local attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.5\(2\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(2\)s:*:*:*:*:*:*:* | ||
15.5\(3\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)s:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.