CVE-2015-4685: High severity polycom realpresence resource manager vulnerability
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, related to a sudo misconfiguration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4685?
CVE-2015-4685 has a medium severity rating due to its potential impact on local user privilege escalation.
How do I fix CVE-2015-4685?
To mitigate CVE-2015-4685, upgrade Polycom RealPresence Resource Manager to version 8.4 or later.
Who is affected by CVE-2015-4685?
Local users with access to the plcm account on Polycom RealPresence Resource Manager versions prior to 8.4 are affected by CVE-2015-4685.
What vulnerabilities does CVE-2015-4685 expose?
CVE-2015-4685 exposes a privilege escalation vulnerability due to a sudo misconfiguration in the script directory.
Is CVE-2015-4685 being actively exploited?
There have been no confirmed reports of active exploitation of CVE-2015-4685, but the risk remains for unpatched systems.