PT-2016-1639 · Cisco+1 · Mobility Services Engine+3

Publicado

2016-04-06

·

Atualizado

2016-12-03

·

CVE-2015-6313

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Server versions 4.1(2.29) through 4.2(4.17) Mobility Services Engine (MSE) version 8710 Multiparty Media versions 310, 320, and 820 Virtual Machine (VM) devices (affected versions not specified)
Description The issue is related to resource management errors, allowing remote attackers to cause a denial of service, either by consuming memory or causing the device to reload, via crafted HTTP requests that are not followed by an unspecified negotiation.
Recommendations For Cisco TelePresence Server versions 4.1(2.29) through 4.2(4.17), update to a version outside of this range to resolve the issue. For Mobility Services Engine (MSE) version 8710, update to a version outside of this range to resolve the issue. For Multiparty Media versions 310, 320, and 820, update to a version outside of this range to resolve the issue. For Virtual Machine (VM) devices, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00951
CVE-2015-6313

Produtos afetados

Cisco Telepresence Server
Mobility Services Engine
Multiparty Media
Virtual Machine