CVE Vulnerabilities

CVE-2015-4185

Published: Jun 13, 2015 | Modified: Jan 04, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.

Affected Software

Name Vendor Start Version End Version
Ios Cisco 15.2(4)m6 (including) 15.2(4)m6 (including)
Ios Cisco 15.2m (including) 15.2m (including)

References