CVE-2015-0682
published 2015-04-03CVE-2015-0682: Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID…
PriorityP338medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.09%
79.5th percentile
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mqh-2fw5-cwj5: Cisco Unified Communications Domain Manager 8
ghsa_unreviewed·2022-05-17
CVE-2015-0682 [MEDIUM] GHSA-4mqh-2fw5-cwj5: Cisco Unified Communications Domain Manager 8
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168.
Cisco
Cisco Unified Communications Domain Manager Application Software Remote Code Execution Vulnerability
vendor_cisco·2015-03-31·CVSS 6.5
CVE-2015-0682 [MEDIUM] Cisco Unified Communications Domain Manager Application Software Remote Code Execution Vulnerability
Cisco Unified Communications Domain Manager Application Software Remote Code Execution Vulnerability
A vulnerability in a deprecated page in Cisco Unified Communications Domain Manager Application Software could allow an authenticated, remote attacker to execute arbitrary code.
The vulnerability is due to insufficient security restrictions imposed by the affected software that could allow arbitrary code execution. An authenticated, remote attacker could exploit this vulnerability to execute arbitrary code in the security context of the application. A successful exploit could be leveraged to conduct further attacks.
Cisco has confirmed the vulnerability and software updates available.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-03
Published