CVE-2015-4185: Cisco IOS

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.

Affected products

  • Cisco IOS: version 15.2(4)m6 only; version 15.2m only

Published 2015-06-13. Last modified 2026-06-17.