CVE-2015-0660

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
14/03/2015
Last modified:
12/04/2025

Description

Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSphere controller administrative privileges, aka Bug ID CSCus61123.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:telepresence_server_software:*:*:*:*:*:*:*:*