CVE-2015-4185

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
13/06/2015
Last modified:
12/04/2025

Description

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ios:15.2\(4\)m6:*:*:*:*:*:*:*
cpe:2.3:o:cisco:ios:15.2m:*:*:*:*:*:*:*