The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1032581 | third party advisory vdb entry |
http://www.securityfocus.com/bid/72310 | third party advisory vdb entry |
http://tools.cisco.com/security/center/viewAlert.x?alertId=39343 | vendor advisory |