CVE-2015-0652
published 2015-03-13CVE-2015-0652: The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.90%
77.2th percentile
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | expressway_software | <= x8.1.1 | — |
| cisco | telepresence_conductor | <= xc2.4 | — |
| cisco | telepresence_conductor | — | — |
| cisco | telepresence_video_communication_server_software | <= x8.1.1 | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9vf2-2mrh-qg3j: The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8
ghsa_unreviewed·2022-05-17
CVE-2015-0652 [HIGH] CWE-20 GHSA-9vf2-2mrh-qg3j: The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
vendor_cisco·2015-03-11·CVSS 10.0
CVE-2015-0652 [CRITICAL] CWE-287 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
Cisco TelePresence Video Communication Server (VCS), Cisco Expressway and Cisco TelePresence Conductor contain the following vulnerabilities:
SDP Media Description Denial of Service Vulnerability
Authentication Bypass Vulnerability
Successful exploitation of the SDP Media Description Denial of Service Vulnerability may
cause the affected system to reload.
Successful exploitation of the Authentication Bypass Vulnerability may allow an attacker to
bypass authentication and log in to the system with the privileges of an administrator.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are not av
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
vendor_cisco
CVE-2015-0652 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
CVE-2015-0652: Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
Cisco TelePresence Video Communication Server (VCS), Cisco Expressway and Cisco TelePresence Conductor contain the following vulnerabilities: SDP Media Description Denial of Service Vulnerability Authentication Bypass Vulnerability Successful exploitation of the SDP Media Description Denial of Service Vulnerability may cause the affected system to reload. Successful exploitation of the Authentication Bypass Vulnerability may allow an attacker to bypass authentication and log in to the system with the privileges of an administrator. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-287, CWE-399, CWE-287, CWE-399
Bug IDs:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-13
Published