CVE-2015-4325
published 2015-10-12CVE-2015-4325: The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges by…
PriorityP423medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.39%
31.1th percentile
The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges by terminating a firestarter.py supervised process and then triggering the restart of a process by the root account, aka Bug ID CSCuv12272.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_expressway | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server (VCS) Expressway Privilege Escalation Vulnerability
vendor_cisco·2015-10-06·CVSS 6.6
CVE-2015-4325 [MEDIUM] CWE-264 Cisco TelePresence Video Communication Server (VCS) Expressway Privilege Escalation Vulnerability
Cisco TelePresence Video Communication Server (VCS) Expressway Privilege Escalation Vulnerability
A vulnerability in the process management code of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, local attacker to run arbitrary programs with elevated privileges.
The vulnerability is due to the failure to protect a supervised process. An attacker could exploit this vulnerability by completing a series of steps that ultimately allows a lower-privileged process to be restarted with root privilege. An attacker would need to crash a firestarter.py supervised process before the privilege is escalated after the process is restarted. A successful exploit could allow the attacker to gain elevated privileges on the device, which could result in a co
Cisco
Cisco TelePresence Video Communication Server (VCS) Expressway Privilege Escalation Vulnerability
vendor_cisco
CVE-2015-4325 Cisco TelePresence Video Communication Server (VCS) Expressway Privilege Escalation Vulnerability
CVE-2015-4325: Cisco TelePresence Video Communication Server (VCS) Expressway Privilege Escalation Vulnerability
A vulnerability in the process management code of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, local attacker to run arbitrary programs with elevated privileges. The vulnerability is due to the failure to protect a supervised process. An attacker could exploit this vulnerability by completing a series of steps that ultimately allows a lower-privileged process to be restarted with root privilege. An attacker would need to crash a firestarter.py supervised process before the privilege is escalated after the process is restarted. A successful exploit could allow the attacker to gain elevated privileges on the device, which could r
GHSA
GHSA-g737-hc9q-f5p5: The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-4325 [MEDIUM] GHSA-g737-hc9q-f5p5: The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8
The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges by terminating a firestarter.py supervised process and then triggering the restart of a process by the root account, aka Bug ID CSCuv12272.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-12
Published