Cisco TelePresence Server 4.1(2.29) through 4.2(4.17) on 7010; Mobility Services Engine (MSE) 8710; Multiparty Media 310, 320, and 820; and Virtual Machine (VM) devices allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted HTTP requests that are not followed by an unspecified negotiation, aka Bug ID CSCuv47565.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCisco Telepresence Server 7010
HWCiscoall versionsCisco Telepresence Server Mse 8710
HWCiscoall versionsCisco Telepresence Server On Multiparty Media 310
HWCiscoall versionsCisco Telepresence Server On Multiparty Media 320
HWCiscoall versionsCisco Telepresence Server On Multiparty Media 820
HWCiscoall versionsCisco Telepresence Server On Virtual Machine
HWCiscoall versionsSun Opensolaris
OSSunsnv_124Zyxel Gs1900 10hp Firmware
OSZyxel< 2.50\(aazi.0\)c0Zzinc Keymouse Firmware
OSZzinc3.08
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
Related vulnerabilities
CVE-2019-15803CRITICAL9.1PL ✓same product
Zyxel GS1900: Auth Bypass w ukrytej powłoce diagnostycznej
CVE-2019-15800CRITICAL9.8PL ✓same product
Zyxel GS1900 — command injection w bibliotece libclicmd.so (RCE)
CVE-2016-1291CRITICAL9.8PL ✓same product
RCE przez deserializację w Cisco Prime Infrastructure i EPNM
CVE-2016-1329CRITICAL9.8PL ✓same product
Cisco NX-OS: Hardcoded credentials umożliwiające zdalny dostęp root
CVE-2015-6319CRITICAL9.8PL ✓same product
SQL injection w interfejsie zarządzania Cisco RV220W