Denial of Service Vulnerability in Cisco Meeting Server Web Bridge
CVE-2023-20255

5.3MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
1 November 2023

Summary

A vulnerability within the API of the Web Bridge feature of Cisco Meeting Server allows unauthenticated remote attackers to disrupt service by exploiting insufficient validation of HTTP requests. By sending specially crafted HTTP packets to the affected device, an attacker can initiate a denial of service (DoS) condition. This could lead to interruptions in ongoing video calls, as the invalid packets cause instability within the Web Bridge, potentially dropping active connections and affecting overall service availability.

Affected Version(s)

Cisco Meeting Server

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.