CVE-2014-2156
published 2014-05-02CVE-2014-2156: Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.17%
63.7th percentile
Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45739.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_system_mxp_series | — | — |
| cisco | telepresence_system_software | <= f9.3 | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco·2014-04-30·CVSS 7.5
CVE-2014-2156 [HIGH] CWE-399 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities:
Three SIP denial of service vulnerabilities
Three H.225 denial of service vulnerabilities
Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload.
Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco
CVE-2014-2156 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
CVE-2014-2156: Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities: Three SIP denial of service vulnerabilities Three H.225 denial of service vulnerabilities Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvi
GHSA
GHSA-rfvh-48qx-c843: Cisco TelePresence System MXP Series Software before F9
ghsa_unreviewed·2022-05-17
CVE-2014-2156 [HIGH] CWE-20 GHSA-rfvh-48qx-c843: Cisco TelePresence System MXP Series Software before F9
Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45739.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-02
Published