CVE-2015-0713

critical
Published 2015-05-25 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.0

Description

The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5 before 4.5(1.45), Cisco TelePresence MSE Supervisor Software before 2.3(1.38), Cisco TelePresence Serial Gateway Series Software before 1.0(1.42), Cisco TelePresence Server Software for Hardware before 3.1(1.98), and Cisco TelePresence Server Software for Virtual Machine before 4.1(1.79) allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors, aka Bug IDs CSCul55968, CSCur08993, CSCur15803, CSCur15807, CSCur15825, CSCur15832, CSCur15842, CSCur15850, and CSCur15855.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
cisco ciscotelepresence_advanced_media_gateway1.0\(.1.13\)
cisco ciscotelepresence_advanced_media_gateway1.1\(.1.14\)
cisco ciscotelepresence_advanced_media_gateway1.1\(1.34\)
cisco ciscotelepresence_ip_gateway2.0.1.7
cisco ciscotelepresence_ip_gateway2.0.1.11
cisco ciscotelepresence_ip_gateway2.0.3.34
cisco ciscotelepresence_ip_vcr_1.0_converter1.0\(1.9\)
cisco ciscotelepresence_ip_vcr_2.41.2
cisco ciscotelepresence_ip_vcr_3.01.22
cisco ciscotelepresence_ip_vcr_3.01.24
cisco ciscotelepresence_isdn_gw_32412.0\(1.51\)
cisco ciscotelepresence_isdn_gw_32412.1\(1.22\)
cisco ciscotelepresence_isdn_gw_32412.1\(1.43\)
cisco ciscotelepresence_isdn_gw_32412.1\(1.49\)
cisco ciscotelepresence_isdn_gw_32412.1\(1.56\)
cisco ciscotelepresence_mcu_software4.1\(1.51\)
cisco ciscotelepresence_mcu_software4.1\(1.59\)
cisco ciscotelepresence_mcu_software4.2\(1.43\)
cisco ciscotelepresence_mcu_software4.2\(1.46\)
cisco ciscotelepresence_mcu_software4.2\(1.50\)
cisco ciscotelepresence_mcu_software4.3\(1.68\)
cisco ciscotelepresence_mcu_software4.3\(2.18\)
cisco ciscotelepresence_mcu_software4.3\(2.30\)
cisco ciscotelepresence_mcu_software4.3\(2.32\)
cisco ciscotelepresence_mcu_software4.4\(3.42\)
cisco ciscotelepresence_mcu_software4.4\(3.49\)
cisco ciscotelepresence_serial_gateway1.0.1.23
cisco ciscotelepresence_serial_gateway1.0.1.34
cisco ciscotelepresence_serial_gateway1.0.1.38
cisco ciscotelepresence_server_software2.1\(1.33\)
cisco ciscotelepresence_server_software2.1\(1.37\)
cisco ciscotelepresence_server_software2.2\(1.43\)
cisco ciscotelepresence_server_software2.2\(1.48\)
cisco ciscotelepresence_server_software2.2\(1.54\)
cisco ciscotelepresence_server_software2.3\(1.55\)
cisco ciscotelepresence_server_software2.3\(1.57\)
cisco ciscotelepresence_server_software3.0\(2.24\)
cisco ciscotelepresence_server_software4.0\(1.57\)
cisco ciscotelepresence_server_software4.0\(2.8\)
cisco ciscotelepresence_supervisor_mse_8050_software2.1\(1.18\)
cisco ciscotelepresence_supervisor_mse_8050_software2.2\(1.17\)
cisco ciscotelepresence_supervisor_mse_8050_software2.3\(1.32\)

References

CWEs

CWE-264

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.