CVE-2014-3369
published 2014-10-19CVE-2014-3369: The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a…
PriorityP433high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.37%
81.8th percentile
The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | expressway_software | <= x8.1 | — |
| cisco | telepresence_video_communication_server_and_cisco_expressway | — | — |
| cisco | telepresence_video_communication_server_software | <= x8.1 | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vh9m-r2xx-pvv5: The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8
ghsa_unreviewed·2022-05-17
CVE-2014-3369 [HIGH] GHSA-vh9m-r2xx-pvv5: The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8
The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
vendor_cisco·2014-10-15·CVSS 7.8
CVE-2014-3368 [HIGH] CWE-20 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Software includes the following vulnerabilities:
Cisco TelePresence VCS and Cisco Expressway Crafted Packets Denial of Service Vulnerability
Cisco TelePresence VCS and Cisco Expressway SIP IX Filter Denial of Service Vulnerability
Cisco TelePresence VCS and Cisco Expressway SIP Denial of Service Vulnerability
Succesfull exploitation of any of these vulnerabilities could allow an unauthenticated, remote attacker to cause a reload of the affected system, which may result in a Denial of Service (DoS) condition.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these v
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
vendor_cisco
CVE-2014-3369 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
CVE-2014-3369: Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Software includes the following vulnerabilities: Cisco TelePresence VCS and Cisco Expressway Crafted Packets Denial of Service Vulnerability Cisco TelePresence VCS and Cisco Expressway SIP IX Filter Denial of Service Vulnerability Cisco TelePresence VCS and Cisco Expressway SIP Denial of Service Vulnerability Succesfull exploitation of any of these vulnerabilities could allow an unauthenticated, remote attacker to cause a reload of the affected system, which may result in a Denial of Service (DoS) condition. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-20, CWE-399,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/60850http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141015-vcshttp://tools.cisco.com/security/center/viewAlert.x?alertId=35828http://www.securitytracker.com/id/1031055http://secunia.com/advisories/60850http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141015-vcshttp://tools.cisco.com/security/center/viewAlert.x?alertId=35828http://www.securitytracker.com/id/1031055
2014-10-19
Published