VulnerabilityModified
CVE-2015-4303
Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333.
MEDIUM 6.5EPSS 2.34%
Does this matter?
Lower severity and a low EPSS score (2.34%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.34% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/telepresence video communication server software
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=40433Vendor Advisory
- http://www.securityfocus.com/bid/76322
- http://www.securitytracker.com/id/1033268
- http://tools.cisco.com/security/center/viewAlert.x?alertId=40433Vendor Advisory
- http://www.securityfocus.com/bid/76322
- http://www.securitytracker.com/id/1033268
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.