Cisco Meeting Server vulnerabilities

9 known vulnerabilities affecting cisco/cisco_meeting_server.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2023-20255MEDIUMCVSS 5.3vN/A2023-11-01
CVE-2023-20255 [MEDIUM] CWE-20 CVE-2023-20255: A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthent A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP packets to an affected device. A successfu
cvelistv5nvd
CVE-2021-40122HIGHCVSS 7.5vn/a2021-10-21
CVE-2021-40122 [MEDIUM] CWE-399 CVE-2021-40122: A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthen A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An attacker could exploit this vulnerability by sending a series of messages to the vulnerable A
cvelistv5nvd
CVE-2021-1524MEDIUMCVSS 6.5vn/a2021-06-16
CVE-2021-1524 [MEDIUM] CWE-20 CVE-2021-1524: A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. An attacker could exploit this vulnerability by sending a malicious request to the API. A succ
cvelistv5nvd
CVE-2020-3160MEDIUMCVSS 5.3≥ unspecified, < n/a2020-02-19
CVE-2020-3160 [MEDIUM] CWE-20 CVE-2020-3160: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Se A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other applications and processes are unaffected. The vulnerability is due to improper input validation
cvelistv5nvd
CVE-2019-1623MEDIUMCVSS 6.7≥ unspecified, < 2.2.142019-06-20
CVE-2019-1623 [MEDIUM] CWE-77 CVE-2019-1623: A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability b
cvelistv5nvd
CVE-2019-1676HIGHCVSS 7.5≥ unspecified, < 2.3.92019-02-08
CVE-2019-1676 [MEDIUM] CWE-20 CVE-2019-1676: A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CM A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Cisco Meeting Server. The vulnerability is due to insufficient validation of Session Description Protocol (SDP) messages. An attacker could ex
cvelistv5nvd
CVE-2019-1678MEDIUMCVSS 4.3≥ unspecified, < 2.4.32019-02-07
CVE-2019-1678 [MEDIUM] CWE-20 CVE-2019-1678: A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a par A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol (SIP) endpoint. The vulnerability is due to improper validation of coSpaces configuration parameters. An attacker could exploit this vulner
cvelistv5nvd
CVE-2018-15446HIGHCVSS 7.5vn/a2018-11-08
CVE-2018-15446 [MEDIUM] CWE-200 CVE-2018-15446: A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain acce A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper protections on data that is returned from user meeting requests when the Guest access via ID and passcode option is set to Legacy mode. An attacker could exploit this vulnerability by s
cvelistv5nvd
CVE-2018-0439HIGHCVSS 8.8vn/a2018-10-05
CVE-2018-0439 [HIGH] CWE-352 CVE-2018-0439: A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthe A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An
cvelistv5nvd