CVE-2014-3370
published 2014-10-19CVE-2014-3370: Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload)…
PriorityP433high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
2.34%
81.6th percentile
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | expressway_software | <= x8.1 | — |
| cisco | telepresence_video_communication_server_and_cisco_expressway | — | — |
| cisco | telepresence_video_communication_server_software | <= x8.1 | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
vendor_cisco·2014-10-15·CVSS 7.8
CVE-2014-3368 [HIGH] CWE-20 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Software includes the following vulnerabilities:
Cisco TelePresence VCS and Cisco Expressway Crafted Packets Denial of Service Vulnerability
Cisco TelePresence VCS and Cisco Expressway SIP IX Filter Denial of Service Vulnerability
Cisco TelePresence VCS and Cisco Expressway SIP Denial of Service Vulnerability
Succesfull exploitation of any of these vulnerabilities could allow an unauthenticated, remote attacker to cause a reload of the affected system, which may result in a Denial of Service (DoS) condition.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these v
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
vendor_cisco
CVE-2014-3370 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
CVE-2014-3370: Multiple Vulnerabilities in Cisco TelePresence Video Communication Server and Cisco Expressway Software
Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Software includes the following vulnerabilities: Cisco TelePresence VCS and Cisco Expressway Crafted Packets Denial of Service Vulnerability Cisco TelePresence VCS and Cisco Expressway SIP IX Filter Denial of Service Vulnerability Cisco TelePresence VCS and Cisco Expressway SIP Denial of Service Vulnerability Succesfull exploitation of any of these vulnerabilities could allow an unauthenticated, remote attacker to cause a reload of the affected system, which may result in a Denial of Service (DoS) condition. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-20, CWE-399,
GHSA
GHSA-f666-7q5v-fcx5: Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8
ghsa_unreviewed·2022-05-17
CVE-2014-3370 [HIGH] GHSA-f666-7q5v-fcx5: Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/60850http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141015-vcshttp://tools.cisco.com/security/center/viewAlert.x?alertId=35829http://www.securitytracker.com/id/1031055http://secunia.com/advisories/60850http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141015-vcshttp://tools.cisco.com/security/center/viewAlert.x?alertId=35829http://www.securitytracker.com/id/1031055
2014-10-19
Published