7.1
CVSSv2

CVE-2013-1176

Published: 18/04/2013 Updated: 19/04/2013
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The DSP card on Cisco TelePresence MCU 4500 and 4501 devices prior to 4.3(2.30), TelePresence MCU MSE 8510 devices prior to 4.3(2.30), and TelePresence Server prior to 2.3(1.55) does not properly validate H.264 data, which allows remote malicious users to cause a denial of service (device reload) via crafted RTP packets in a (1) SIP session or (2) H.323 session, aka Bug IDs CSCuc11328 and CSCub05448.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence_mcu_4500_series_software 4.1\\(1.59\\)

cisco telepresence_mcu_4500_series_software

cisco telepresence_mcu_4500_series_software 4.2\\(1.46\\)

cisco telepresence_mcu_4500_series_software 4.1\\(1.51\\)

cisco telepresence_mcu_4500_series_software 4.3\\(1.68\\)

cisco telepresence_mcu_4500_series_software 4.2\\(1.50\\)

cisco telepresence_mcu_4500_series_software 4.2\\(1.43\\)

cisco telepresence_mcu_4520 -

cisco telepresence_mcu_4515 -

cisco telepresence_mcu_4505 -

cisco telepresence_mcu_4510 -

cisco telepresence_mcu_4501_series_software 4.1\\(1.51\\)

cisco telepresence_mcu_4501_series_software

cisco telepresence_mcu_4501_series_software 4.3\\(1.68\\)

cisco telepresence_mcu_4501_series_software 4.2\\(1.50\\)

cisco telepresence_mcu_4501_series_software 4.2\\(1.46\\)

cisco telepresence_mcu_4501_series_software 4.2\\(1.43\\)

cisco telepresence_mcu_4501_series_software 4.1\\(1.59\\)

cisco telepresence_mcu_4501 -

cisco telepresence_mcu_mse_series_software 4.3\\(1.68\\)

cisco telepresence_mcu_mse_series_software 4.2\\(1.46\\)

cisco telepresence_mcu_mse_series_software 4.1\\(1.51\\)

cisco telepresence_mcu_mse_series_software 4.1\\(1.59\\)

cisco telepresence_mcu_mse_series_software

cisco telepresence_mcu_mse_series_software 4.2\\(1.50\\)

cisco telepresence_mcu_mse_series_software 4.2\\(1.43\\)

cisco telepresence_mcu_mse_8510 -

cisco telepresence_server_software 2.1\\(1.33\\)

cisco telepresence_server_software

cisco telepresence_server_software 2.1\\(1.37\\)

cisco telepresence_server_software 2.2\\(1.43\\)

cisco telepresence_server_7010 -

cisco telepresence_server_mse_8710 -

Vendor Advisories

Cisco TelePresence multipoint control unit (MCU) and Cisco TelePresence Server contain a vulnerability that could allow an unauthenticated, remote attacker to trigger the reload of an affected system Cisco has released software updates that address this vulnerability Workarounds that mitigate this vulnerability are not available This advisory i ...