PT-2017-16123 · Cisco · Cisco Telepresence Collaboration Endpoint
Published
2017-05-16
·
Updated
2017-07-11
·
CVE-2017-3825
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco TelePresence Collaboration Endpoint (CE) Software versions CE8.1.1 through CE8.3.1
Description
A vulnerability in the ICMP ingress packet processing could allow an unauthenticated, remote attacker to cause the TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. This is due to incomplete input validation for the size of a received ICMP packet. An attacker could exploit this by sending a crafted ICMP packet to the local IP address of the targeted endpoint, potentially causing calls to be dropped. The vulnerability affects either IPv4 or IPv6 ICMP traffic.
Recommendations
For versions CE8.1.1 through CE8.3.1, update to a fixed software release to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Telepresence Collaboration Endpoint