Routing Vulnerability in Oracle Communications Session Border Controller
CVE-2021-2416

4.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

A vulnerability exists in Oracle Communications Session Border Controller that allows a high-privileged attacker with network access via HTTP to compromise the system. This flaw could enable unauthorized users to cause system hangs or frequent crashes, leading to denial of service to legitimate users. The affected versions are 8.4 and 9.0, and it is critical for organizations to monitor and remediate to prevent exploitation.

Affected Version(s)

Communications Session Border Controller 8.4

Communications Session Border Controller 9.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.