CVE-2015-0717
published 2015-05-16CVE-2015-0717: Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID…
PriorityP423medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.36%
28.4th percentile
Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID CSCut19546.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager root Shell Access Local Privilege Escalation Vulnerability
vendor_cisco·2015-05-08·CVSS 6.9
CVE-2015-0717 [MEDIUM] CWE-264 Cisco Unified Communications Manager root Shell Access Local Privilege Escalation Vulnerability
Cisco Unified Communications Manager root Shell Access Local Privilege Escalation Vulnerability
A vulnerability in the local read file of the Cisco Unified Communications Manager could allow an authenticated, local attacker to execute commands and obtain an interactive Linux shell as the root user if the attacker has already obtained sensitive information from the system.
The vulnerability is due to a failure to properly sanitize user input. An attacker could exploit this vulnerability by inserting Linux shell commands into a parameter using common techniques. A successful exploit could allow the attacker to execute any command on the Linux shell as the root user, which could result in a complete system compromise.
Cisco has confirmed the vulnerability and released software updates.
T
GHSA
GHSA-2pg2-fqwq-2432: Cisco Unified Communications Manager 10
ghsa_unreviewed·2022-05-17
CVE-2015-0717 [MEDIUM] CWE-20 GHSA-2pg2-fqwq-2432: Cisco Unified Communications Manager 10
Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID CSCut19546.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-16
Published