CVE-2017-12362

MEDIUM

Cisco Meeting Server < 2.2.2 - Authenticated Denial of Service via Video Call

Title source: llm
STIX 2.1

Description

A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems with a particular configuration. An attacker could exploit this by knowing a valid URI that directs to a Cisco Meeting Server. An attacker could then make a video call and cause the system to reload. Cisco Bug IDs: CSCve65931.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039913
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101987

Scores

CVSS v3 6.5
EPSS 0.0235
EPSS Percentile 81.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (2)
cisco/meeting_server < 2.2.2
n/a/Cisco Meeting Server Cisco Meeting Server
Published Nov 30, 2017
Tracked Since Feb 18, 2026