PT-2013-2944 · Cisco · Cisco Telepresence Mcu Mse 8510+3
Publicado
2013-04-18
·
Atualizado
2013-04-19
·
CVE-2013-1176
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco TelePresence MCU 4500 versions prior to 4.3(2.30)
Cisco TelePresence MCU 4501 versions prior to 4.3(2.30)
Cisco TelePresence MCU MSE 8510 versions prior to 4.3(2.30)
Cisco TelePresence Server versions prior to 2.3(1.55)
Description
The issue allows remote attackers to cause a denial of service, resulting in a device reload, by sending crafted RTP packets in a SIP session or an H.323 session. This is due to the DSP card not properly validating H.264 data.
Recommendations
For Cisco TelePresence MCU 4500 versions prior to 4.3(2.30), update to version 4.3(2.30) or later.
For Cisco TelePresence MCU 4501 versions prior to 4.3(2.30), update to version 4.3(2.30) or later.
For Cisco TelePresence MCU MSE 8510 versions prior to 4.3(2.30), update to version 4.3(2.30) or later.
For Cisco TelePresence Server versions prior to 2.3(1.55), update to version 2.3(1.55) or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Telepresence Mcu 4500
Cisco Telepresence Mcu 4501
Cisco Telepresence Mcu Mse 8510
Cisco Telepresence Server