Improper input validation in Cisco Meeting Server - CVE-2017-3830

 

Improper input validation in Cisco Meeting Server - CVE-2017-3830

Published: February 15, 2017 / Updated: April 5, 2018


Vulnerability identifier: #VU5854
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3830
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to cause denial of service.

The vulnerability exists due to improper input validation when processing requests sent to port 2829/TCP in internal API of the Cisco Meeting Server (CMS). A remote unauthenticated attacker can send a specially crafted request to port 2829/TCP and cause denial of service.

Successful exploitation of the vulnerability may allow an attacker to perform denial of service (DoS) attack against vulnerable service.



Affected software

Cisco Meeting Server

How to mitigate CVE-2017-3830

Install update from vendor's website.


External References

Related Security Bulletins