Denial of Service Risk in Cisco TelePresence Advanced Media Gateway
CVE-2019-15966

7.7HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
5 November 2019

Summary

A significant vulnerability within the web application of the Cisco TelePresence Advanced Media Gateway can be exploited by an authenticated remote attacker, resulting in a denial of service (DoS) condition. This weakness stems from insufficient input validation, enabling the attacker to craft a specialized HTTP request that, when sent to the device, can disrupt its operations. The outcome may leave the device inoperable, effectively denying service to legitimate users and potentially leading to significant operational disruptions.

Affected Version(s)

Cisco TelePresence Advanced Media Gateway 1.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.