Input validation error in Cisco Meeting Server - CVE-2019-1676

 

Input validation error in Cisco Meeting Server - CVE-2019-1676

Published: February 7, 2019


Vulnerability identifier: #VU17424
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1676
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) due to insufficient validation of Session Description Protocol (SDP) messages. A remote attacker can send a specially crafted SDP message to the CMS call bridge and cause the CMS to reload, causing a DoS condition for all connected clients.


Affected software

Cisco Meeting Server

How to mitigate CVE-2019-1676

The vulnerability has been fixed in the versions 2.3.9, 2.2.14.

Cisco Meeting Server - addressed in versions 2.2.14, 2.3.9

External References

Related Security Bulletins