7.8
CVSSv2

CVE-2017-6648

Published: 08/06/2017 Updated: 03/10/2019
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote malicious user to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms within the software. An attacker could exploit this vulnerability by sending a flood of SIP INVITE packets to the affected device. An exploit could allow the malicious user to impact the availability of services and data of the device, including a complete DoS condition. This vulnerability affects the following Cisco TC and CE platforms when running software versions prior to TC 7.3.8 and CE 8.3.0. Cisco Bug IDs: CSCux94002.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence tc software 5.1.4

cisco telepresence tc software 6.0.2

cisco telepresence tc software 6.3.2

cisco telepresence tc software 4.1_base

cisco telepresence tc software 6.1.1-cucm

cisco telepresence tc software 7.3.2

cisco telepresence tc software 5.1_base

cisco telepresence tc software 5.1.3-cucm

cisco telepresence tc software 5.1.6-cucm

cisco telepresence tc software 5.1.7

cisco telepresence tc software 7.1.4

cisco telepresence tc software 6.1.2-cucm

cisco telepresence tc software 7.3.6

cisco telepresence tc software 7.1.0

cisco telepresence tc software 4.1.2

cisco telepresence tc software 6.3.0

cisco telepresence tc software 6.0.1-cucm

cisco telepresence tc software 4.2.0

cisco telepresence tc software 6.1.0

cisco telepresence tc software 4.2.1

cisco telepresence tc software 6.3.1

cisco telepresence tc software 6.0.3

cisco telepresence tc software 7.3.7

cisco telepresence tc software 7.1.2

cisco telepresence tc software 5.1.5-cucm

cisco telepresence tc software 7.2.0

cisco telepresence tc software 6.3.5

cisco telepresence tc software 7.3.0

cisco telepresence tc software 5.0.2-cucm

cisco telepresence tc software 7.2.1

cisco telepresence tc software 5.1.11

cisco telepresence tc software 8.2.0

cisco telepresence tc software 3.1_base

cisco telepresence tc software 6.0.0-cucm

cisco telepresence tc software 7.3.3

cisco telepresence tc software 4.2.2

cisco telepresence tc software 7.1.1

cisco telepresence tc software 6.0_base

cisco telepresence tc software 4.1.0

cisco telepresence tc software 4.2.3

cisco telepresence tc software 5.1.5

cisco telepresence tc software 6.1.1

cisco telepresence tc software 6.1_base

cisco telepresence tc software 3.1.5

cisco telepresence tc software 7.1.3

cisco telepresence tc software 4.2_base

cisco telepresence tc software 6.1.4

cisco telepresence tc software 5.1.3

cisco telepresence tc software 6.3.4

cisco telepresence tc software 7.3.1

cisco telepresence ce software 8.2.2

cisco telepresence tc software 5.1.7-cucm

cisco telepresence tc software 6.3.3

cisco telepresence tc software 6.0.1

cisco telepresence tc software 5.0.2

cisco telepresence tc software 5.1.13

cisco telepresence tc software 5.0_base

cisco telepresence tc software 5.1.4-cucm

cisco telepresence tc software 6.0.4

cisco telepresence tc software 4.2.4

cisco telepresence tc software 4.1.1

cisco telepresence tc software 6.1.0-cucm

cisco telepresence tc software 6.1.2

cisco telepresence tc software 8.2.1

cisco telepresence tc software 5.1.6

cisco telepresence tc software 6.0.0

cisco telepresence tc software 6.1.3

Vendor Advisories

A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition The vulnerability is due to a lack of flow-control mechanis ...