VulnerabilityModified
CVE-2015-4185
The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
MEDIUM 6.9EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/ios
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39343Vendor Advisory
- http://www.securityfocus.com/bid/72310Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032581Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/viewAlert.x?alertId=39343Vendor Advisory
- http://www.securityfocus.com/bid/72310Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1032581Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.