CVE-2015-0772
published 2015-06-12CVE-2015-0772: Cisco TelePresence Video Communication Server (VCS) X8.5RC4 allows remote attackers to cause a denial of service (CPU consumption or device outage) via a…
PriorityP430high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.87%
77.0th percentile
Cisco TelePresence Video Communication Server (VCS) X8.5RC4 allows remote attackers to cause a denial of service (CPU consumption or device outage) via a crafted SDP parameter-negotiation request in an SDP session during a SIP connection, aka Bug ID CSCut42422.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server SDP Over SIP Denial of Service Vulnerability
vendor_cisco·2015-06-09·CVSS 7.1
CVE-2015-0772 [HIGH] CWE-399 Cisco TelePresence Video Communication Server SDP Over SIP Denial of Service Vulnerability
Cisco TelePresence Video Communication Server SDP Over SIP Denial of Service Vulnerability
A vulnerability in the Session Description Protocol (SDP) parser of the Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause the Cisco VCS device to become unreachable due to a denial of service (DoS) attack caused by high CPU utilization.
The vulnerability is due to a parsing error in the SDP parameter negotiation request. An attacker could exploit this vulnerability by initiating an SDP session over a Session Initiation Protocol (SIP) connection to the Cisco VCS device and sending a crafted SDP parameter negotiation request. A successful exploit could allow the attacker to take the VCS device offline due to high CPU utilization, resulting in
GHSA
GHSA-jxhf-r3w6-4pgq: Cisco TelePresence Video Communication Server (VCS) X8
ghsa_unreviewed·2022-05-17
CVE-2015-0772 [HIGH] GHSA-jxhf-r3w6-4pgq: Cisco TelePresence Video Communication Server (VCS) X8
Cisco TelePresence Video Communication Server (VCS) X8.5RC4 allows remote attackers to cause a denial of service (CPU consumption or device outage) via a crafted SDP parameter-negotiation request in an SDP session during a SIP connection, aka Bug ID CSCut42422.
No detection rules found.
No writeups or analysis indexed.
2015-06-12
Published