CVE-2015-4185

Cisco IOS 15.2 - Local Privilege Escalation via TCL Interpreter VTY State

Title source: llm
STIX 2.1

Description

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032581
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72310
Vendor Advisory vendor-advisory x_refsource_cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=39343

Scores

EPSS 0.0044
EPSS Percentile 35.6%

Details

CWE
CWE-264
Status published
Products (2)
cisco/ios 15.2\(4\)m6
cisco/ios 15.2m
Published Jun 13, 2015
Tracked Since Feb 18, 2026