CVE-2016-6448
published 2016-11-03CVE-2016-6448: A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary…
PriorityP264critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.98%
89.3th percentile
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server_session_description_protocol_media_lines | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted SDP packets with oversized media lines targeting the SDP parser of Cisco Meeting Server, which can trigger a buffer overflow (CWE-119) ↗
- →Focus inspection on SDP media line ('m=') field sizes in inbound SDP session descriptions for abnormally large or malformed values indicative of exploitation attempts ↗
- ·Affected versions are Cisco Meeting Server prior to 2.0.3, Acano Server 1.9.x prior to 1.9.5, and Acano Server 1.8.x prior to 1.8.17; detections should be prioritized on unpatched instances in these version ranges ↗
- ·No workarounds are available; detection/blocking of malformed SDP traffic is the only mitigation short of patching ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability
vendor_cisco·2016-11-02·CVSS 7.5
CVE-2016-6448 [HIGH] CWE-119 Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability
Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system.
The vulnerability exists because the affected software performs incomplete input validation of the size of media lines in session descriptions. An attacker could exploit this vulnerability by sending crafted packets to the SDP parser on an affected system. A successful exploit could allow the attacker to cause a buffer overflow condition on an affected system, which could allow the attacker to execute arbitrary code on the system.
Cisco has released software updates that address this vulnerability. There are no wo
Cisco
Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability
vendor_cisco
CVE-2016-6448 Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability
CVE-2016-6448: Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software performs incomplete input validation of the size of media lines in session descriptions. An attacker could exploit this vulnerability by sending crafted packets to the SDP parser on an affected system. A successful exploit could allow the attacker to cause a buffer overflow condition on an affected system, which could allow the attacker to execute arbitrary code on the system. Cisco has released software updates that address this vulnerability. The
GHSA
GHSA-rp77-2mhc-jvcr: A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute ar
ghsa_unreviewed·2022-05-17
CVE-2016-6448 [CRITICAL] CWE-119 GHSA-rp77-2mhc-jvcr: A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute ar
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94076http://www.securitytracker.com/id/1037181https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1http://www.securityfocus.com/bid/94076http://www.securitytracker.com/id/1037181https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1
2016-11-03
Published