Skip to content

A vulnerability in the Tool Command Language (Tcl)...

High severity Unreviewed Published Apr 16, 2022 to the GitHub Advisory Database • Updated Mar 6, 2024

Package

No package listedSuggest a package

Affected versions

Unknown

Patched versions

Unknown

Description

A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-level privileges. This vulnerability is due to insufficient input validation of data that is passed into the Tcl interpreter. An attacker could exploit this vulnerability by loading malicious Tcl code on an affected device. A successful exploit could allow the attacker to execute arbitrary commands as root. By default, Tcl shell access requires privilege level 15.

References

Published by the National Vulnerability Database Apr 15, 2022
Published to the GitHub Advisory Database Apr 16, 2022
Last updated Mar 6, 2024

Severity

High

EPSS score

0.042%
(5th percentile)

CVE ID

CVE-2022-20676

GHSA ID

GHSA-mm24-m3qx-g7j8

Source code

No known source code

Dependabot alerts are not supported on this advisory because it does not have a package from a supported ecosystem with an affected and fixed version.

Learn more about GitHub language support

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.