CVE Database
/

CVE-2017-6648

Back to search

CVE-2017-6648

Published: Jun 8, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms within the software. An attacker could exploit this vulnerability by sending a flood of SIP INVITE packets to the affected device. An exploit could allow the attacker to impact the availability of services and data of the device, including a complete DoS condition. This vulnerability affects the following Cisco TC and CE platforms when running software versions prior to TC 7.3.8 and CE 8.3.0. Cisco Bug IDs: CSCux94002.

VendorProductVersions

n/a

Cisco TelePresence Endpoint Denial of Service Vulnerability

affected
Cisco TelePresence Endpoint Denial of Service Vulnerability

Weaknesses (CWE)

References

98934
vdb-entry
x_refsource_BID
1038624
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now