Remote code execution in Cisco Meeting Server - CVE-2016-6448

 

Remote code execution in Cisco Meeting Server - CVE-2016-6448

Published: November 2, 2016 / Updated: April 5, 2018


Vulnerability identifier: #VU1139
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6448
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to execute arbitrary code on the target system
The weakness is due to improper input validation. By sending a specially crafted Session Description Protocol (SDP) packets, a remote attacker can cayse a buffer overflow in the processing of media lines in the SDP parser and execute arbitrary code.
Successful exploitation of the vulnerability results in arbitrary code execution.

Affected software

Cisco Meeting Server

How to mitigate CVE-2016-6448

Update to version 2.0.3.


External References

Related Security Bulletins