CVE-2015-4276
published 2015-07-16CVE-2015-4276: Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.
PriorityP340medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.55%
83.2th percentile
Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | webex_meetings_server | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6jh7-v9q8-2jq6: Cisco WebEx Meetings Server 2
ghsa_unreviewed·2022-05-17
CVE-2015-4276 [MEDIUM] CWE-20 GHSA-6jh7-v9q8-2jq6: Cisco WebEx Meetings Server 2
Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.
Cisco
Cisco WebEx Meetings Server Remote Code Execution Vulnerability
vendor_cisco·2015-07-15·CVSS 6.5
CVE-2015-4276 [MEDIUM] CWE-20 Cisco WebEx Meetings Server Remote Code Execution Vulnerability
Cisco WebEx Meetings Server Remote Code Execution Vulnerability
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system.
The vulnerability is due to insufficient sanitization of user-supplied input. An attacker could exploit this vulnerability by sending crafted data in a command parameter to an affected system. A successful exploit could allow the attacker to execute arbitrary code on the affected system, which could be leveraged to conduct further attacks.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement reduces the likelihood of a successful exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-16
Published