CVE-2016-6446
published 2016-10-27CVE-2016-6446: A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More…
PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.40%
69.4th percentile
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Meeting Server Information Disclosure Vulnerability
vendor_cisco·2016-10-19·CVSS 5.0
CVE-2016-6446 [MEDIUM] CWE-200 Cisco Meeting Server Information Disclosure Vulnerability
Cisco Meeting Server Information Disclosure Vulnerability
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server.
The vulnerability is due to missing bounds checks in the Web Bridge functionality. An attacker could exploit this vulnerability by sending a crafted packet to the affected server. An exploit could allow the attacker to disclose a portion of memory from the server for every packet. The disclosed portions of memory could contain sensitive information such as private keys or passwords.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.c
Cisco
Cisco Meeting Server Information Disclosure Vulnerability
vendor_cisco
CVE-2016-6446 Cisco Meeting Server Information Disclosure Vulnerability
CVE-2016-6446: Cisco Meeting Server Information Disclosure Vulnerability
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. The vulnerability is due to missing bounds checks in the Web Bridge functionality. An attacker could exploit this vulnerability by sending a crafted packet to the affected server. An exploit could allow the attacker to disclose a portion of memory from the server for every packet. The disclosed portions of memory could contain sensitive information such as private keys or passwords. Cisco has released software updates that address this vulnerability.
CWE: CWE-200, CWE-200
Bug IDs: CSCvb03308
GHSA
GHSA-cxgx-fvxg-j7j4: A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server
ghsa_unreviewed·2022-05-17
CVE-2016-6446 [HIGH] CWE-200 GHSA-cxgx-fvxg-j7j4: A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-10-27
Published