cbcvebase.
CVE-2016-6448
published 2016-11-03

CVE-2016-6448: A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary…

PriorityP264critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.98%
89.3th percentile
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.

Affected

10 ranges
VendorProductVersion rangeFixed in
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server
ciscomeeting_server_session_description_protocol_media_lines

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted SDP packets with oversized media lines targeting the SDP parser of Cisco Meeting Server, which can trigger a buffer overflow (CWE-119)
  • Focus inspection on SDP media line ('m=') field sizes in inbound SDP session descriptions for abnormally large or malformed values indicative of exploitation attempts
  • ·Affected versions are Cisco Meeting Server prior to 2.0.3, Acano Server 1.9.x prior to 1.9.5, and Acano Server 1.8.x prior to 1.8.17; detections should be prioritized on unpatched instances in these version ranges
  • ·No workarounds are available; detection/blocking of malformed SDP traffic is the only mitigation short of patching

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.