CVE-2015-4327
published 2015-08-20CVE-2015-4327: The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script arguments to an…
PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.41%
33.4th percentile
The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script arguments to an unspecified file, aka Bug ID CSCuv12542.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server Expressway Arbitrary File Injection Vulnerability
vendor_cisco·2015-08-18·CVSS 7.2
CVE-2015-4327 [HIGH] CWE-20 Cisco TelePresence Video Communication Server Expressway Arbitrary File Injection Vulnerability
Cisco TelePresence Video Communication Server Expressway Arbitrary File Injection Vulnerability
A vulnerability in the command-line interface (CLI) of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, local attacker to inject arbitrary arguments to a script on an affected system.
The vulnerability is due to insufficient input validation of content on a local file. An attacker could exploit this vulnerability by writing arbitrary code to the affected file. An exploit could allow the attacker to write options to a file that has root privileges.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate and have local access to the targeted device. These ac
GHSA
GHSA-h92v-j4j5-v87x: The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-4327 [HIGH] CWE-20 GHSA-h92v-j4j5-v87x: The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8
The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script arguments to an unspecified file, aka Bug ID CSCuv12542.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-20
Published