Denial of Service in Cisco Expressway Series and TelePresence Software
CVE-2017-12287

4.3MEDIUM

Key Information:

Summary

A vulnerability in the cluster database management component of Cisco Expressway Series Software and Cisco TelePresence VCS Software allows an authenticated remote attacker to exploit incomplete input validation of URL requests via the REST API. By sending a specially crafted URL, an attacker could trigger unexpected restarts of the CDB process on affected systems, leading to temporary service disruptions. For more details, please refer to Cisco's security advisory and related Bug IDs.

Affected Version(s)

Cisco Expressway Series and Cisco TelePresence Video Communication Server Cisco Expressway Series and Cisco TelePresence Video Communication Server

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.