cbcvebase.
CVE-2015-0652
published 2015-03-13

CVE-2015-0652: The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco…

PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.90%
77.2th percentile
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscoexpressway_software<= x8.1.1
ciscotelepresence_conductor<= xc2.4
ciscotelepresence_conductor
ciscotelepresence_video_communication_server_software<= x8.1.1

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.