CVE-2015-4303
published 2015-08-20CVE-2015-4303: Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user…
PriorityP337medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.34%
81.6th percentile
Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-52gm-mw2g-p3w8: Cisco TelePresence Video Communication Server (VCS) X8
ghsa_unreviewed·2022-05-17
CVE-2015-4303 [MEDIUM] GHSA-52gm-mw2g-p3w8: Cisco TelePresence Video Communication Server (VCS) X8
Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333.
Cisco
Cisco TelePresence Video Communication Server Command Injection Vulnerability
vendor_cisco·2015-08-12·CVSS 6.5
CVE-2015-4303 [MEDIUM] CWE-78 Cisco TelePresence Video Communication Server Command Injection Vulnerability
Cisco TelePresence Video Communication Server Command Injection Vulnerability
A vulnerability in the web framework in the Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to inject arbitrary commands that are executed at the nobody
privilege level.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the affected parameter in a web page. The user must be authenticated in order to access the affected parameter. A successful exploit could allow an attacker to execute commands at the nobody privilege level.
Cisco has confirmed the vulnerability and released updated software.
To exploit this vulnerability, an attacker requires
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-20
Published