CVE-2015-6312
published 2016-04-06CVE-2015-6312: Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.93%
77.7th percentile
Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_server_malformed_stun_packet_processing | — | — |
| dell | emc_powerscale_onefs | — | — |
| netgear | jr6150_firmware | < 2017-01-06 | 2017-01-06 |
| zyxel | gs1900-10hp_firmware | < 2.50\(aazi.0\)c0 | 2.50\(aazi.0\)c0 |
| zzinc | keymouse_firmware | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability
vendor_cisco·2016-04-06·CVSS 7.8
CVE-2015-6312 [HIGH] CWE-119 Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability
Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability
A vulnerability in Cisco TelePresence Server devices running software version 3.1 could allow an unauthenticated, remote attacker to reload the device.
The vulnerability exists due to a failure to properly process malformed Session Traversal Utilities for NAT (STUN) packets. An attacker could exploit this vulnerability by submitting malformed STUN packets to the device. If successful, the attacker could force the device to reload and drop all calls in the process.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/conten
Cisco
Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability
vendor_cisco
CVE-2015-6312 Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability
CVE-2015-6312: Cisco TelePresence Server Malformed STUN Packet Processing Denial of Service Vulnerability
A vulnerability in Cisco TelePresence Server devices running software version 3.1 could allow an unauthenticated, remote attacker to reload the device. The vulnerability exists due to a failure to properly process malformed Session Traversal Utilities for NAT (STUN) packets. An attacker could exploit this vulnerability by submitting malformed STUN packets to the device. If successful, the attacker could force the device to reload and drop all calls in the process. Cisco has released software updates that address this vulnerability.
CWE: CWE-119, CWE-119
Bug IDs: CSCuv01348
GHSA
GHSA-q9cj-g23q-m8r7: Cisco TelePresence Server 3
ghsa_unreviewed·2022-05-17
CVE-2015-6312 [HIGH] CWE-119 GHSA-q9cj-g23q-m8r7: Cisco TelePresence Server 3
Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (device reload) via malformed STUN packets, aka Bug ID CSCuv01348.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-04-06
Published