CVE-2015-4185: Medium severity cisco ios vulnerability
The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4185?
CVE-2015-4185 has a medium severity rating due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2015-4185?
To fix CVE-2015-4185, upgrade to a non-vulnerable version of Cisco IOS that addresses this specific vulnerability.
Who is affected by CVE-2015-4185?
CVE-2015-4185 affects local users of Cisco IOS versions 15.2(4)m6 and 15.2m who can manipulate the vty state.
Is CVE-2015-4185 exploitable remotely?
CVE-2015-4185 is not directly exploitable remotely as it requires local access to the system.
What types of devices are impacted by CVE-2015-4185?
CVE-2015-4185 impacts devices running the vulnerable versions of Cisco IOS mentioned in the vulnerability report.