CVE-2015-4683 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 6.9% (pctl 94)
Patch early
A public exploit exists.
Description
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.87% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-09-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| polycom | realpresence resource manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities | 2015-06-30 |
References
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.html
- http://seclists.org/fulldisclosure/2015/Jun/81
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432
- https://support.polycom.com/global/documents/support/documentation/Security_Center_Post_for_RPRM_CVEs.pdf
- https://www.exploit-db.com/exploits/37449/
- http://packetstormsecurity.com/files/132463/Polycom-RealPresence-Resource-Manager-RPRM-Disclosure-Traversal.html
- http://seclists.org/fulldisclosure/2015/Jun/81
- http://www.securityfocus.com/archive/1/535852/100/0/threaded
- http://www.securityfocus.com/bid/75432
- https://support.polycom.com/global/documents/support/documentation/Security_Center_Post_for_RPRM_CVEs.pdf
- https://www.exploit-db.com/exploits/37449/
→ the Explorer · watch your stack · NVD