Lucene search

K
ciscoCiscoCISCO-SA-20150217-CVE-2015-0621
HistoryFeb 17, 2015 - 8:24 p.m.

Cisco TelePresence Multipoint Control Unit Denial of Service Vulnerability

2015-02-1720:24:29
tools.cisco.com
9

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.014

Percentile

86.2%

A vulnerability in the Cisco TelePresence multipoint control unit (MCU) could allow an unauthenticated, remote attacker to trigger a reload of an affected system.

The vulnerability is due to insufficient sanitization of TCP packets. An attacker could exploit this vulnerability by sending a sequence of TCP packets to the affected system.

Cisco has confirmed the vulnerability in a security notice and released software updates.

To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send a sequence of TCP packets to the targeted system. This access requirement may reduce the likelihood of a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscotelepresence_mcu_softwareMatchany
OR
ciscotelepresence_mcu_softwareMatchany
VendorProductVersionCPE
ciscotelepresence_mcu_softwareanycpe:2.3:a:cisco:telepresence_mcu_software:any:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.014

Percentile

86.2%

Related for CISCO-SA-20150217-CVE-2015-0621