CVE-2016-9224
MEDIUMCisco Jabber Guest Server - SSRF
Title source: llmDescription
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0).
Scores
CVSS v3
6.5
EPSS
0.0030
EPSS Percentile
52.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Classification
CWE
CWE-20
Status
published
Affected Products (6)
cisco/jabber_guest
cisco/jabber_guest
cisco/jabber_guest
cisco/jabber_guest
cisco/jabber_guest
n/a/Cisco Jabber Guest Server 10.6(9)
< Cisco Jabber Guest Server 10.6(9)
Timeline
Published
Dec 26, 2016
Tracked Since
Feb 18, 2026