CVE Vulnerabilities

CVE-2017-6648

Published: Jun 08, 2017 | Modified: Oct 03, 2019
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms within the software. An attacker could exploit this vulnerability by sending a flood of SIP INVITE packets to the affected device. An exploit could allow the attacker to impact the availability of services and data of the device, including a complete DoS condition. This vulnerability affects the following Cisco TC and CE platforms when running software versions prior to TC 7.3.8 and CE 8.3.0. Cisco Bug IDs: CSCux94002.

Affected Software

Name Vendor Start Version End Version
Telepresence_ce_software Cisco 8.2.2 (including) 8.2.2 (including)
Telepresence_tc_software Cisco 3.1.5 (including) 3.1.5 (including)
Telepresence_tc_software Cisco 3.1_base (including) 3.1_base (including)
Telepresence_tc_software Cisco 4.1.0 (including) 4.1.0 (including)
Telepresence_tc_software Cisco 4.1.1 (including) 4.1.1 (including)
Telepresence_tc_software Cisco 4.1.2 (including) 4.1.2 (including)
Telepresence_tc_software Cisco 4.1_base (including) 4.1_base (including)
Telepresence_tc_software Cisco 4.2.0 (including) 4.2.0 (including)
Telepresence_tc_software Cisco 4.2.1 (including) 4.2.1 (including)
Telepresence_tc_software Cisco 4.2.2 (including) 4.2.2 (including)
Telepresence_tc_software Cisco 4.2.3 (including) 4.2.3 (including)
Telepresence_tc_software Cisco 4.2.4 (including) 4.2.4 (including)
Telepresence_tc_software Cisco 4.2_base (including) 4.2_base (including)
Telepresence_tc_software Cisco 5.0.2 (including) 5.0.2 (including)
Telepresence_tc_software Cisco 5.0.2-cucm (including) 5.0.2-cucm (including)
Telepresence_tc_software Cisco 5.0_base (including) 5.0_base (including)
Telepresence_tc_software Cisco 5.1.3 (including) 5.1.3 (including)
Telepresence_tc_software Cisco 5.1.3-cucm (including) 5.1.3-cucm (including)
Telepresence_tc_software Cisco 5.1.4 (including) 5.1.4 (including)
Telepresence_tc_software Cisco 5.1.4-cucm (including) 5.1.4-cucm (including)
Telepresence_tc_software Cisco 5.1.5 (including) 5.1.5 (including)
Telepresence_tc_software Cisco 5.1.5-cucm (including) 5.1.5-cucm (including)
Telepresence_tc_software Cisco 5.1.6 (including) 5.1.6 (including)
Telepresence_tc_software Cisco 5.1.6-cucm (including) 5.1.6-cucm (including)
Telepresence_tc_software Cisco 5.1.7 (including) 5.1.7 (including)
Telepresence_tc_software Cisco 5.1.7-cucm (including) 5.1.7-cucm (including)
Telepresence_tc_software Cisco 5.1.11 (including) 5.1.11 (including)
Telepresence_tc_software Cisco 5.1.13 (including) 5.1.13 (including)
Telepresence_tc_software Cisco 5.1_base (including) 5.1_base (including)
Telepresence_tc_software Cisco 6.0.0 (including) 6.0.0 (including)
Telepresence_tc_software Cisco 6.0.0-cucm (including) 6.0.0-cucm (including)
Telepresence_tc_software Cisco 6.0.1 (including) 6.0.1 (including)
Telepresence_tc_software Cisco 6.0.1-cucm (including) 6.0.1-cucm (including)
Telepresence_tc_software Cisco 6.0.2 (including) 6.0.2 (including)
Telepresence_tc_software Cisco 6.0.3 (including) 6.0.3 (including)
Telepresence_tc_software Cisco 6.0.4 (including) 6.0.4 (including)
Telepresence_tc_software Cisco 6.0_base (including) 6.0_base (including)
Telepresence_tc_software Cisco 6.1.0 (including) 6.1.0 (including)
Telepresence_tc_software Cisco 6.1.0-cucm (including) 6.1.0-cucm (including)
Telepresence_tc_software Cisco 6.1.1 (including) 6.1.1 (including)
Telepresence_tc_software Cisco 6.1.1-cucm (including) 6.1.1-cucm (including)
Telepresence_tc_software Cisco 6.1.2 (including) 6.1.2 (including)
Telepresence_tc_software Cisco 6.1.2-cucm (including) 6.1.2-cucm (including)
Telepresence_tc_software Cisco 6.1.3 (including) 6.1.3 (including)
Telepresence_tc_software Cisco 6.1.4 (including) 6.1.4 (including)
Telepresence_tc_software Cisco 6.1_base (including) 6.1_base (including)
Telepresence_tc_software Cisco 6.3.0 (including) 6.3.0 (including)
Telepresence_tc_software Cisco 6.3.1 (including) 6.3.1 (including)
Telepresence_tc_software Cisco 6.3.2 (including) 6.3.2 (including)
Telepresence_tc_software Cisco 6.3.3 (including) 6.3.3 (including)
Telepresence_tc_software Cisco 6.3.4 (including) 6.3.4 (including)
Telepresence_tc_software Cisco 6.3.5 (including) 6.3.5 (including)
Telepresence_tc_software Cisco 7.1.0 (including) 7.1.0 (including)
Telepresence_tc_software Cisco 7.1.1 (including) 7.1.1 (including)
Telepresence_tc_software Cisco 7.1.2 (including) 7.1.2 (including)
Telepresence_tc_software Cisco 7.1.3 (including) 7.1.3 (including)
Telepresence_tc_software Cisco 7.1.4 (including) 7.1.4 (including)
Telepresence_tc_software Cisco 7.2.0 (including) 7.2.0 (including)
Telepresence_tc_software Cisco 7.2.1 (including) 7.2.1 (including)
Telepresence_tc_software Cisco 7.3.0 (including) 7.3.0 (including)
Telepresence_tc_software Cisco 7.3.1 (including) 7.3.1 (including)
Telepresence_tc_software Cisco 7.3.2 (including) 7.3.2 (including)
Telepresence_tc_software Cisco 7.3.3 (including) 7.3.3 (including)
Telepresence_tc_software Cisco 7.3.6 (including) 7.3.6 (including)
Telepresence_tc_software Cisco 7.3.7 (including) 7.3.7 (including)
Telepresence_tc_software Cisco 8.2.0 (including) 8.2.0 (including)
Telepresence_tc_software Cisco 8.2.1 (including) 8.2.1 (including)

References