CVE-2016-9207
MEDIUMCisco Expressway - DoS
Title source: llmDescription
A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. Affected Products: This vulnerability affects Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS). More Information: CSCvc10834. Known Affected Releases: X8.7.2 X8.8.3. Known Fixed Releases: X8.9.
Scores
CVSS v3
6.5
EPSS
0.0081
EPSS Percentile
74.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Classification
CWE
CWE-254
CWE-20
Status
published
Affected Products (3)
cisco/expressway
cisco/expressway
n/a/Cisco Expressway
< Cisco Expressway
Timeline
Published
Dec 14, 2016
Tracked Since
Feb 18, 2026