PT-2013-2944 · Cisco · Cisco Telepresence Mcu Mse 8510+3

Publicado

2013-04-18

·

Atualizado

2013-04-19

·

CVE-2013-1176

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco TelePresence MCU 4500 versions prior to 4.3(2.30) Cisco TelePresence MCU 4501 versions prior to 4.3(2.30) Cisco TelePresence MCU MSE 8510 versions prior to 4.3(2.30) Cisco TelePresence Server versions prior to 2.3(1.55)
Description The issue allows remote attackers to cause a denial of service, resulting in a device reload, by sending crafted RTP packets in a SIP session or an H.323 session. This is due to the DSP card not properly validating H.264 data.
Recommendations For Cisco TelePresence MCU 4500 versions prior to 4.3(2.30), update to version 4.3(2.30) or later. For Cisco TelePresence MCU 4501 versions prior to 4.3(2.30), update to version 4.3(2.30) or later. For Cisco TelePresence MCU MSE 8510 versions prior to 4.3(2.30), update to version 4.3(2.30) or later. For Cisco TelePresence Server versions prior to 2.3(1.55), update to version 2.3(1.55) or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1176

Produtos afetados

Cisco Telepresence Mcu 4500
Cisco Telepresence Mcu 4501
Cisco Telepresence Mcu Mse 8510
Cisco Telepresence Server