Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-6648

EPSS 0.73% · P73
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-6648

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms within the software. An attacker could exploit this vulnerability by sending a flood of SIP INVITE packets to the affected device. An exploit could allow the attacker to impact the availability of services and data of the device, including a complete DoS condition. This vulnerability affects the following Cisco TC and CE platforms when running software versions prior to TC 7.3.8 and CE 8.3.0. Cisco Bug IDs: CSCux94002.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
资源管理错误
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco TelePresence Codec和Collaboration Endpoint软件资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco TelePresence是美国思科(Cisco)公司的一套被称为“网真”系统的视频会议解决方案。TelePresence Codec(TC)和Collaboration Endpoint(CE)Software是其中的两个终端软件。 Cisco TC软件7.3.8之前的版本和CE软件8.3.0之前的版本中的Session Initiation Protocol (SIP)存在拒绝服务漏洞,该漏洞源于程序缺少流量控制机制。远程攻击者可通过向受到影响的设备发送大量的SIP INVITE数据包利用该
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Cisco TelePresence Endpoint Denial of Service Vulnerability Cisco TelePresence Endpoint Denial of Service Vulnerability -

II. Public POCs for CVE-2017-6648

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-6648

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-06-08 · 50 CVEs total

CVE-2017-5878Red5 Media Server 安全漏洞
CVE-2017-9517AtMail 跨站请求伪造漏洞
CVE-2017-6638Cisco AnyConnect Secure Mobility Client for Windows 权限许可和访问控制问题漏洞
CVE-2017-6639Cisco Prime Data Center Network Manager for Microsoft Windows、Linux和Virtual Appliance平台安全漏
CVE-2017-6640Cisco Prime Data Center Network Manager 安全漏洞
CVE-2017-9516Craft CMS 跨站脚本漏洞
CVE-2017-7180Net Monitor for Employees Pro 代码问题漏洞
CVE-2017-9520radare2 安全漏洞
CVE-2017-9022strongSwan 输入验证错误漏洞
CVE-2017-8108Lynis 安全漏洞
CVE-2017-9023strongSwan ASN.1解析器安全漏洞
CVE-2015-2800多款华为产品user authentication模块安全漏洞
CVE-2015-2255Huawei AR1220 安全漏洞
CVE-2015-2253Huawei OceanStor UDS 信息泄露漏洞
CVE-2015-2252Huawei OceanStor UDS 代码注入漏洞
CVE-2015-2251Huawei OceanStor UDS DeviceManager 信息泄露漏洞
CVE-2014-8687Seagate Business NAS 安全漏洞
CVE-2014-6031多款F5产品缓冲区错误漏洞
CVE-2014-4843IBM Curam Social Program Management Curam Universal Access 安全漏洞
CVE-2016-4471Red Hat CloudForms ManageIQ 权限许可和访问控制漏洞

Showing top 20 of 50 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-6648

No comments yet


Leave a comment