CVE-2015-4327: Input Validation
Published Aug 20, 2015
·Updated
The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script arguments to an unspecified file, aka Bug ID CSCuv12542.
Affected Software
1 affected component
Cisco Telepresence Video Communication Server Software=x8.5.2
Event History
Aug 20, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4327?
CVE-2015-4327 has a medium severity rating due to the potential for local users to gain root privileges.
2
How do I fix CVE-2015-4327?
To fix CVE-2015-4327, upgrade to a version of Cisco TelePresence Video Communication Server that addresses this vulnerability.
3
Who is affected by CVE-2015-4327?
CVE-2015-4327 affects local users of Cisco TelePresence Video Communication Server Expressway version X8.5.2.
4
What type of attack does CVE-2015-4327 involve?
CVE-2015-4327 involves a local privilege escalation attack that allows users to gain root access.
5
Is CVE-2015-4327 exploitable remotely?
CVE-2015-4327 is not remotely exploitable as it requires local user access to the system.