ID

VAR-201505-0192


CVE

CVE-2015-0750


TITLE

Cisco Hosted Collaboration Solution Management Web An arbitrary command execution vulnerability in the interface

Trust: 0.8

sources: JVNDB: JVNDB-2015-002798

DESCRIPTION

The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786. An attacker can exploit this issue to execute system commands on the affected device. This issue being tracked by Cisco Bug ID CSCut02786. The solution includes products such as Cisco TelePresence, Customer Collaboration (Contact Center) and Unified Communications to support customers to use collaboration technology in public cloud, private cloud and hybrid cloud models

Trust: 1.98

sources: NVD: CVE-2015-0750 // JVNDB: JVNDB-2015-002798 // BID: 74796 // VULHUB: VHN-78696

AFFECTED PRODUCTS

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.5\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.1\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.5\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.1\(2\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.2\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:8.6\(2\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:8.0\(2\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:8.6\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.1\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.0\(1\)_base

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.6\(2\)_base

Trust: 1.0

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.0\(1\)_base

Trust: 1.0

vendor:ciscomodel:hosted collaboration solutionscope:lteversion:10.6(1)

Trust: 0.8

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.5(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.2(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.1(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.0(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:8.6(2)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:8.6(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:8.0(2)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.6(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.5(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.1(2)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.1(1)

Trust: 0.3

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:10.0(1)

Trust: 0.3

sources: BID: 74796 // JVNDB: JVNDB-2015-002798 // CNNVD: CNNVD-201505-484 // NVD: CVE-2015-0750

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0750
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0750
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201505-484
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78696
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0750
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-78696
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-78696 // JVNDB: JVNDB-2015-002798 // CNNVD: CNNVD-201505-484 // NVD: CVE-2015-0750

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-78696 // JVNDB: JVNDB-2015-002798 // NVD: CVE-2015-0750

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201505-484

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201505-484

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002798

PATCH

title:38969url:http://tools.cisco.com/security/center/viewAlert.x?alertId=38969

Trust: 0.8

sources: JVNDB: JVNDB-2015-002798

EXTERNAL IDS

db:NVDid:CVE-2015-0750

Trust: 2.8

db:JVNDBid:JVNDB-2015-002798

Trust: 0.8

db:CNNVDid:CNNVD-201505-484

Trust: 0.7

db:BIDid:74796

Trust: 0.4

db:VULHUBid:VHN-78696

Trust: 0.1

sources: VULHUB: VHN-78696 // BID: 74796 // JVNDB: JVNDB-2015-002798 // CNNVD: CNNVD-201505-484 // NVD: CVE-2015-0750

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=38969

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0750

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0750

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-78696 // BID: 74796 // JVNDB: JVNDB-2015-002798 // CNNVD: CNNVD-201505-484 // NVD: CVE-2015-0750

CREDITS

Cisco

Trust: 0.3

sources: BID: 74796

SOURCES

db:VULHUBid:VHN-78696
db:BIDid:74796
db:JVNDBid:JVNDB-2015-002798
db:CNNVDid:CNNVD-201505-484
db:NVDid:CVE-2015-0750

LAST UPDATE DATE

2025-04-13T23:23:45.039000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-78696date:2015-05-26T00:00:00
db:BIDid:74796date:2015-05-22T00:00:00
db:JVNDBid:JVNDB-2015-002798date:2015-05-27T00:00:00
db:CNNVDid:CNNVD-201505-484date:2015-05-25T00:00:00
db:NVDid:CVE-2015-0750date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-78696date:2015-05-23T00:00:00
db:BIDid:74796date:2015-05-22T00:00:00
db:JVNDBid:JVNDB-2015-002798date:2015-05-27T00:00:00
db:CNNVDid:CNNVD-201505-484date:2015-05-25T00:00:00
db:NVDid:CVE-2015-0750date:2015-05-23T01:59:00.077