6.9

CVE-2015-4185

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Version 15.2m
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.44% 0.346
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://tools.cisco.com/security/center/viewAlert.x?alertId=39343
Vendor Advisory
http://www.securityfocus.com/bid/72310
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1032581
Third Party Advisory
VDB Entry