CVE-2014-3369

Severity
7.1HIGH
EPSS
0.7%
top 28.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateMay 17

Description

The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.

CVSS vector

AV:N/AC:M/C:N/I:N/A:CExploitability: 8.6 | Impact: 6.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-vh9m-r2xx-pvv5: The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X82022-05-17
CVEList
CVE-2014-3369: The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X82014-10-19

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software2014-10-15
CVE-2014-3369 (HIGH CVSS 7.1) | The SIP IX implementation in Cisco | cvebase.io