CVE-2017-6648

HIGH

Cisco TelePresence TC and CE Software - Denial of Service via SIP INVITE Flood

Title source: llm
STIX 2.1

Description

A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms within the software. An attacker could exploit this vulnerability by sending a flood of SIP INVITE packets to the affected device. An exploit could allow the attacker to impact the availability of services and data of the device, including a complete DoS condition. This vulnerability affects the following Cisco TC and CE platforms when running software versions prior to TC 7.3.8 and CE 8.3.0. Cisco Bug IDs: CSCux94002.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98934
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038624

Scores

CVSS v3 7.5
EPSS 0.0356
EPSS Percentile 88.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (50)
cisco/telepresence_ce_software 8.2.2
cisco/telepresence_tc_software 3.1.5
cisco/telepresence_tc_software 3.1_base
cisco/telepresence_tc_software 4.1.0
cisco/telepresence_tc_software 4.1.1
cisco/telepresence_tc_software 4.1.2
cisco/telepresence_tc_software 4.1_base
cisco/telepresence_tc_software 4.2.0
cisco/telepresence_tc_software 4.2.1
cisco/telepresence_tc_software 4.2.2
... and 40 more
Published Jun 08, 2017
Tracked Since Feb 18, 2026