PT-2017-16097 · Cisco · Cisco Telepresence Vcs+1

Published

2017-02-01

·

Updated

2019-10-03

·

CVE-2017-3790

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Expressway Series Software versions prior to X8.8.2 Cisco TelePresence VCS Software versions prior to X8.8.2
Description A vulnerability in the received packet parser could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition. This issue is due to insufficient size validation of user-supplied data. An attacker could exploit this by sending crafted H.224 data in Real-Time Transport Protocol (RTP) packets in an H.323 call, potentially overflowing a buffer in a cache that belongs to the received packet parser and causing a crash of the application.
Recommendations For Cisco Expressway Series Software versions prior to X8.8.2, update to version X8.8.2 or later. For Cisco TelePresence VCS Software versions prior to X8.8.2, update to version X8.8.2 or later.

Fix

DoS

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3790

Affected Products

Cisco Expressway Series
Cisco Telepresence Vcs