CVE-2015-4329
published 2015-08-20CVE-2015-4329: The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS…
PriorityP340medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.29%
81.2th percentile
The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, aka Bug ID CSCuv11796.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
vendor_cisco·2015-08-18·CVSS 6.5
CVE-2015-4329 [MEDIUM] CWE-78 Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
A vulnerability in the administrator web interface of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of a targeted device.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the affected device and submitting crafted HTTP requests. A successful exploit could allow the attacker to execute operating system commands and escalate privileges to increase the level of access to the targeted system.
Cisco has confirmed the vulnerability and software updates are available.
An authenticated, remote attacke
GHSA
GHSA-r242-56ch-cmv2: The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8
ghsa_unreviewed·2022-05-17
CVE-2015-4329 [MEDIUM] CWE-20 GHSA-r242-56ch-cmv2: The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8
The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, aka Bug ID CSCuv11796.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-20
Published