PT-2017-16097 · Cisco · Cisco Telepresence Vcs+1

Publicado

2017-02-01

·

Atualizado

2019-10-03

·

CVE-2017-3790

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Expressway Series Software versions prior to X8.8.2 Cisco TelePresence VCS Software versions prior to X8.8.2
Description A vulnerability in the received packet parser could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition. This issue is due to insufficient size validation of user-supplied data. An attacker could exploit this by sending crafted H.224 data in Real-Time Transport Protocol (RTP) packets in an H.323 call, potentially overflowing a buffer in a cache that belongs to the received packet parser and causing a crash of the application.
Recommendations For Cisco Expressway Series Software versions prior to X8.8.2, update to version X8.8.2 or later. For Cisco TelePresence VCS Software versions prior to X8.8.2, update to version X8.8.2 or later.

Correção

DoS

Buffer Overflow

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3790

Produtos afetados

Cisco Expressway Series
Cisco Telepresence Vcs