cbcvebase.

Cisco Meeting Server vulnerabilities

27 known vulnerabilities affecting cisco/meeting_server.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH11MEDIUM12

Vulnerabilities

Page 1 of 2
CVE-2016-6448P2CRITICALCVSS 9.8v1.8.15v1.8_base+7 more2016-11-03
CVE-2016-6448 [CRITICAL] CWE-119 CVE-2016-6448: A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Se
nvd
CVE-2016-6447P2CRITICALCVSS 9.8v1.8_basev1.9.0+1 more2016-11-03
CVE-2016-6447 [CRITICAL] CWE-119 CVE-2016-6447: A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attac A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to 2.0.1, Acano Server releases prior to 1.8.16 and prior to 1.9.3, Cisco Meeting App releases prior to 1.9.8,
nvd
CVE-2016-6445P2CRITICALCVSS 9.1v1.8.15v1.8_base+7 more2016-10-27
CVE-2016-6445 [CRITICAL] CWE-20 CVE-2016-6445: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meetin A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user. This vulnerability is due to the XMPP service incorrectly processing a deprecated auth
nvd
CVE-2018-0262P3HIGHCVSS 8.1v1.9v2.0+4 more2018-05-02
CVE-2018-0262 [HIGH] CWE-16 CVE-2018-0262: A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unau A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external i
nvd
CVE-2017-12249P3CRITICALCVSS 9.1≤ 2.0.15v2.1.0+16 more2017-09-13
CVE-2017-12249 [CRITICAL] CWE-16 CVE-2017-12249: A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (C A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system. The vulnerability is due to an incorrect default configuration of the TURN server, which
nvd
CVE-2018-0439P3HIGHCVSS 8.8v2.0.0v2.1.0+3 more2018-10-05
CVE-2018-0439 [HIGH] CWE-352 CVE-2018-0439: A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthe A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An
nvd
CVE-2016-6446P3HIGHCVSS 7.5v1.8.15v1.8_base+7 more2016-10-27
CVE-2016-6446 [HIGH] CWE-200 CVE-2016-6446: A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attack A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.
nvd
CVE-2018-0280P3HIGHCVSS 7.5v2.0v2.1+4 more2018-05-17
CVE-2018-0280 [HIGH] CWE-20 CVE-2018-0280: A vulnerability in the Real-Time Transport Protocol (RTP) bitstream processing of the Cisco Meeting A vulnerability in the Real-Time Transport Protocol (RTP) bitstream processing of the Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation of incoming RTP bitstreams. An attacker could exploit this vulnerability by sending a crafted RTP
nvd
CVE-2016-6444P3HIGHCVSS 8.8v1.8.15v1.8_base+7 more2016-10-27
CVE-2016-6444 [HIGH] CWE-352 CVE-2016-6444: A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.
nvd
CVE-2017-3837P3HIGHCVSS 8.1v2.0.0v2.0.1+9 more2017-02-22
CVE-2017-3837 [HIGH] CWE-20 CVE-2017-3837: An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of confidential information. In addition, the attacker could potentially cause the application to crash une
nvd
CVE-2017-6763P3HIGHCVSS 7.5v2.1.42017-08-07
CVE-2017-6763 [HIGH] CWE-20 CVE-2017-6763: A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 coul A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected application does not properly validate Fragmentation Unit (FU-A) protocol packets. An attacker cou
nvd
CVE-2017-3830P3HIGHCVSS 7.5v2.1.02017-02-22
CVE-2017-3830 [HIGH] CWE-20 CVE-2017-3830: A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected appliance. More Information: CSCvc89678. Known Affected Releases: 2.1. Known Fixed Releases: 2.1.2.
nvd
CVE-2019-1676P3HIGHCVSS 7.5≥ 2.3.0, < 2.3.92019-02-08
CVE-2019-1676 [HIGH] CWE-20 CVE-2019-1676: A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CM A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Cisco Meeting Server. The vulnerability is due to insufficient validation of Session Description Protocol (SDP) messages. An attacker could expl
nvd
CVE-2021-40122P3HIGHCVSS 7.5≤ 3.1≥ 3.2, < 3.2.32021-10-21
CVE-2021-40122 [HIGH] CWE-399 CVE-2021-40122: A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthen A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An attacker could exploit this vulnerability by sending a series of messages to the vulnerable API
nvd
CVE-2018-0263P3HIGHCVSS 7.4fixed in 2.2.13fixed in 2.3.42018-06-07
CVE-2018-0263 [HIGH] CWE-16 CVE-2018-0263: A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to a A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external interface of the system. A successful expl
nvd
CVE-2018-0371P3MEDIUMCVSS 6.5v2.2.52018-06-21
CVE-2018-0371 [MEDIUM] CWE-20 CVE-2018-0371: A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, rem A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of incoming HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Web Admin Interface of an affe
nvd
CVE-2017-12362P4MEDIUMCVSS 6.5fixed in 2.2.22017-11-30
CVE-2017-12362 [MEDIUM] CWE-399 CVE-2017-12362: A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems with a particular configuration. An attacker could exploit this by knowing a valid URI that direct
nvd
CVE-2021-1524P4MEDIUMCVSS 6.5≥ 3.1, < 3.1.12021-06-16
CVE-2021-1524 [MEDIUM] CWE-20 CVE-2021-1524: A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. An attacker could exploit this vulnerability by sending a malicious request to the API. A succ
nvd
CVE-2019-1623P4MEDIUMCVSS 6.7≥ 2.2.0, < 2.2.14≥ 2.3.0, < 2.3.82019-06-20
CVE-2019-1623 [MEDIUM] CWE-77 CVE-2019-1623: A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability b
nvd
CVE-2017-6794P4MEDIUMCVSS 6.7v2.0.0v2.0.1+28 more2017-09-07
CVE-2017-6794 [MEDIUM] CWE-20 CVE-2017-6794: A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient validation of user-supplied input
nvd
Cisco Meeting Server vulnerabilities | cvebase