CVE-2015-0750
published 2015-05-23CVE-2015-0750: The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary…
PriorityP337medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.38%
68.9th percentile
The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
| cisco | hosted_collaboration_solution | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco HCS Administrative Web Interface Arbitrary Command Execution Vulnerability
vendor_cisco·2015-05-22·CVSS 6.5
CVE-2015-0750 [MEDIUM] CWE-20 Cisco HCS Administrative Web Interface Arbitrary Command Execution Vulnerability
Cisco HCS Administrative Web Interface Arbitrary Command Execution Vulnerability
A vulnerability in the administrative web interface of Cisco Hosted Collaboration Solution (HCS) could allow an authenticated, remote attacker to execute arbitrary commands on the affected system and on the devices managed by the affected system.
The vulnerability is due to improper user input validation. An attacker could exploit this vulnerability by crafting input into the affected fields of the web interface on a targeted device. A successful exploit could allow the attacker to execute arbitrary commands on the device or on other devices managed by the device, which could be leveraged to conduct further attacks.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulne
GHSA
GHSA-mrjg-qmgr-v7v2: The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10
ghsa_unreviewed·2022-05-17
CVE-2015-0750 [MEDIUM] GHSA-mrjg-qmgr-v7v2: The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10
The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-05-23
Published