vendor:
RealPresence Resource Manager (RPRM)
by:
R. Freingruber, C.A. (Office Vienna)
7
CVSS
HIGH
Unauthenticated Remote Command Execution
N/A
CWE
Product Name: RealPresence Resource Manager (RPRM)
Affected Version From: <8.4
Affected Version To: <8.4
Patch Exists: YES
Related CWE: CVE-2015-4681, CVE-2015-4682, CVE-2015-4683, CVE-2015-4684, CVE-2015-4685
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Critical vulnerabilities allow surveillance on conferences
By combining all vulnerabilities documented in this advisory an unprivileged authenticated remote attacker can gain full system access (root) on the RPRM appliance. This has an impact on all conferences taking place via this RP Resource Manager. Attackers can steal all conference passcodes and join or record any conference.
Mitigation:
Update to version 8.4