CVE-2015-4685: Polycom Realpresence Resource Manager

High severity, CVSS 7.0. EPSS: 1.2% chance of exploitation in the next 30 days.

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, related to a sudo misconfiguration.

Affected products

  • Polycom Realpresence Resource Manager: up to and including 8.3.2

Published 2017-09-19. Last modified 2026-06-17.