CVE-2017-6648
Severity CVSS v4.0:
Pending analysis
Type:
CWE-399
Resource Management Errors
Publication date:
08/06/2017
Last modified:
20/04/2025
Description
A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms within the software. An attacker could exploit this vulnerability by sending a flood of SIP INVITE packets to the affected device. An exploit could allow the attacker to impact the availability of services and data of the device, including a complete DoS condition. This vulnerability affects the following Cisco TC and CE platforms when running software versions prior to TC 7.3.8 and CE 8.3.0. Cisco Bug IDs: CSCux94002.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:telepresence_ce_software:8.2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:3.1.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:3.1_base:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.1_base:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.2.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.2.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.2.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:4.2_base:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:5.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:telepresence_tc_software:5.0.2-cucm:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/98934
- http://www.securitytracker.com/id/1038624
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-tele
- http://www.securityfocus.com/bid/98934
- http://www.securitytracker.com/id/1038624
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-tele



