CVE-2015-4303

Cisco TelePresence Video Communication Server X8.5.2 - Authenticated Remote Code Execution

Title source: llm
STIX 2.1

Description

Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=40433
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76322
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033268

Scores

EPSS 0.0234
EPSS Percentile 81.8%

Details

CWE
CWE-264
Status published
Products (1)
cisco/telepresence_video_communication_server_software x8.5.2
Published Aug 20, 2015
Tracked Since Feb 18, 2026