peter bassill · operator
$ cve CVE-2015-4683 JSON

CVE-2015-4683 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.87% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2017-09-19
Last modified2026-06-17

Affected (1)

VendorProduct
polycomrealpresence resource manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD