Lucene search

K
cveCiscoCVE-2015-4185
HistoryJun 13, 2015 - 10:59 a.m.

CVE-2015-4185

2015-06-1310:59:01
CWE-264
cisco
web.nvd.nist.gov
31
cve-2015-4185
cisco
ios 15.2
privilege escalation
vulnerability
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.

Affected configurations

Nvd
Node
ciscoiosMatch15.2\(4\)m6
OR
ciscoiosMatch15.2m
VendorProductVersionCPE
ciscoios15.2(4)m6cpe:2.3:o:cisco:ios:15.2\(4\)m6:*:*:*:*:*:*:*
ciscoios15.2mcpe:2.3:o:cisco:ios:15.2m:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2015-4185