CVE Vulnerabilities

CVE-2015-4185

Published: Jun 13, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.

Affected Software

NameVendorStart VersionEnd Version
IosCisco15.2(4)m6 (including)15.2(4)m6 (including)
IosCisco15.2m (including)15.2m (including)

References