{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T11:05:11Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20150709-CVE-2015-4244","slug":"cisco-sa-20150709-cve-2015-4244","vendor":"Cisco","title":"Cisco ASR 5000 Series Software Local Command Injection Vulnerability","summary":"A vulnerability in the boot process of the Cisco ASR5000 and ASR5500 (ASK5K) System Software could allow an authenticated, local attacker to cause commands to be executed during the boot process. The vulnerability is due to improper reading of a local file on Compact Flash (CF) during the boot process. An attacker could exploit this vulnerability by logging in as an administrator-privileged user and writing a file to CF with a set of Linux commands. An exploit could allow the attacker to execute this list of unexpected Linux commands at boot time. The commands are contained in the file that was written out by the malicious administrative user. Cisco has confirmed the vulnerability and released software updates. To exploit the vulnerability, an attacker must be able to log in locally to a device and have permissions sufficient to write to the device storage. These access requirements greatly reduce the potential for exploitation.","severity":"Medium","published_at":"2015-07-09T20:51:51Z","updated_at":"2015-07-09T20:51:51Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150709-CVE-2015-4244","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20150709-CVE-2015-4244/csaf/Cisco-SA-20150709-CVE-2015-4244.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.00444},"cves":[{"id":"CVE-2015-4244","kev":false,"epss":{"score":0.00444,"percentile":0.36026,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco ASR 5000 Series Software","slug":"cisco-asr-5000-series-software","vendor":"Cisco"},"cve":{"id":"CVE-2015-4244"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-19T23:31:48Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco ASR 5000 Series Software","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.00444,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2015-07-09T20:51:51Z","updated_at":"2015-07-09T20:51:51Z","advisory_updated_at":"2015-07-09T20:51:51Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20150709-CVE-2015-4244","row_display_order":1}]}