CVE-2015-4277: Cisco NX-OS
Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.
The global-configuration implementation on Cisco ASR 9000 devices with software 5.1.3 and 5.3.0 improperly closes vty sessions after a commit/end operation, which allows local users to cause a denial of service (tmp/*config file creation, memory consumption, and device hang) via unspecified vectors, aka Bug ID CSCut93842.
Affected products
- Cisco NX-OS: version 5.1.3 only; version 5.3.0 only
Published 2015-08-19. Last modified 2026-06-17.