CVE-2016-6445
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
27/10/2016
Last modified:
12/04/2025
Description
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user. This vulnerability is due to the XMPP service incorrectly processing a deprecated authentication scheme. A successful exploit could allow an attacker to access the system as another user.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cisco:meeting_server:1.8.15:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:1.8_base:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:1.9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:1.9.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:2.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:2.0.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:2.0.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:meeting_server:2.0.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-msc
- http://www.securityfocus.com/bid/93517
- http://www.securitytracker.com/id/1037000
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-msc
- http://www.securityfocus.com/bid/93517
- http://www.securitytracker.com/id/1037000