CVE-2015-4685 is a privilege escalation vulnerability affecting Polycom RealPresence Resource Manager (RPRM) versions prior to 8.4. A local attacker with access to the 'plcm' account can exploit a sudo misconfiguration by injecting a malicious script into /var/polycom/cma/upgrade/scripts to gain elevated privileges. This vulnerability has a CVSSv3 score of 7.0 (High), indicating a high potential impact on confidentiality, integrity, and availability, despite requiring local access and high attack complexity. While there is no evidence of active exploitation or Metasploit/Nuclei modules, an ExploitDB entry (EDB-37449) exists, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.3.2CPE matchmatch criteria | cpe:2.3:a:polycom:realpresence_resource_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.