CVE-2015-4185
published 2015-06-13CVE-2015-4185: The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon…
PriorityP422medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.44%
35.2th percentile
The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6gc2-q6xw-3c8q: The TCL interpreter in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-4185 [MEDIUM] GHSA-6gc2-q6xw-3c8q: The TCL interpreter in Cisco IOS 15
The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
Cisco
Cisco IOS Software TCL Script Interpreter Privilege Escalation Vulnerability
vendor_cisco·2015-06-12·CVSS 6.9
CVE-2015-4185 [MEDIUM] CWE-264 Cisco IOS Software TCL Script Interpreter Privilege Escalation Vulnerability
Cisco IOS Software TCL Script Interpreter Privilege Escalation Vulnerability
A vulnerability in the Tool Command Language (TCL) script interpreter of Cisco IOS Software could allow an authenticated, local attacker to escalate privileges from those of a non-privileged user to a privileged (level 15) user. This would allow a non-privileged user to execute privileged commands (those under privilege level 15).
The vulnerability is due to an error when resetting vty privileges after running a TCL script. An attacker could exploit this vulnerability by establishing a session with an affected device immediately after a TCL script has been run. An attacker would need to provide valid credentials and successfully pass authentication to the device.
Cisco has confirmed the vulnerability and releas
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-13
Published