cbcvebase.
CVE-2016-6447
published 2016-11-03

CVE-2016-6447: A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This…

PriorityP263critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.08%
86.2th percentile
A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to 2.0.1, Acano Server releases prior to 1.8.16 and prior to 1.9.3, Cisco Meeting App releases prior to 1.9.8, Acano Meeting Apps releases prior to 1.8.35. More Information: CSCva75942 CSCvb67878. Known Affected Releases: 1.81.92.0.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscomeeting_app
ciscomeeting_app
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server_and_meeting_app

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is crafted IPv6 input sent to the vulnerable function; monitor for malformed/crafted IPv6 packets targeting Cisco Meeting Server or Meeting App endpoints
  • Successful exploitation results in a buffer underflow leading to incorrect memory allocation and potential device reload; unexpected process crashes or device reloads on Cisco Meeting Server may indicate exploitation attempts
  • Track Cisco bug IDs CSCva75942 and CSCvb67878 for patch status; unpatched instances of Cisco Meeting Server < 2.0.1, Acano Server < 1.8.16 / < 1.9.3, Cisco Meeting App < 1.9.8, Acano Meeting Apps < 1.8.35 are vulnerable
  • ·No workarounds are available for this vulnerability; the only mitigation is patching to a fixed software release
  • ·Vulnerability is exploitable by unauthenticated remote attackers, meaning no credentials or prior access are required, significantly raising exposure for internet-facing deployments

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.