Memory corruption in Cisco Expressway and Cisco TelePresence Video Communication Server - CVE-2017-3790
Published: January 25, 2017 / Updated: May 23, 2018
Cisco Expressway
Cisco TelePresence Video Communication Server
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to boundary error when processing h323 calls. A remote unauthenticated attacker can initiate connection to the vulnerable service, send specially crafted h224 data in Real-Time Transport Protocol (RTP) packets, trigger memory corruption and h323 call parser and crash the service.