4.4
CVSSv2

CVE-2015-4685

Published: 19/09/2017 Updated: 09/10/2018
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 445
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Polycom RealPresence Resource Manager (aka RPRM) prior to 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, related to a sudo misconfiguration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

polycom realpresence resource manager

Exploits

By combining all vulnerabilities documented in this advisory an unprivileged authenticated remote attacker can gain full system access (root) on the RPRM appliance This has an impact on all conferences taking place via this RP Resource Manager Attackers can steal all conference passcodes and join or record any conference Versions prior to 84 ar ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SEC Consult Vulnerability Lab Security Advisory < 20150626-0 > ======================================================================= title: Critical vulnerabilities allow surveillance on conferences product: Polycom RealPresence Resource Manager (RPRM) vulnerable versi ...