CVE-2015-4185Cisco IOS vulnerability

CWE-2644 documents4 sources
Severity
6.9MEDIUMNVD
EPSS
0.1%
top 69.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Latest updateMay 17

Description

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

NVDcisco/ios15.2\(4\)m6, 15.2m+1

🔴Vulnerability Details

2
GHSA
GHSA-6gc2-q6xw-3c8q: The TCL interpreter in Cisco IOS 152022-05-17
CVEList
CVE-2015-4185: The TCL interpreter in Cisco IOS 152015-06-13

📋Vendor Advisories

1
Cisco
Cisco IOS Software TCL Script Interpreter Privilege Escalation Vulnerability2015-06-12
CVE-2015-4185 — Cisco IOS vulnerability | cvebase