CVE-2015-4244: Cisco Asr 5000 Series Software

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.

Affected products

  • Cisco Asr 5000 Series Software: version 14.0 only

Published 2015-07-10. Last modified 2026-06-17.