ID

VAR-201306-0171


CVE

CVE-2013-3393


TITLE

Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine Denial of service in Japan (DoS) Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2013-003144

DESCRIPTION

The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117. Cisco Jabber is prone to a denial-of-service vulnerability. An attacker can exploit this issue to crash the various processes or disconnection of any active calls on the device, denying service to legitimate users. This issue is being tracked by Cisco Bug IDs CSCuh60706 and CSCue21117

Trust: 1.98

sources: NVD: CVE-2013-3393 // JVNDB: JVNDB-2013-003144 // BID: 60764 // VULHUB: VHN-63395

AFFECTED PRODUCTS

vendor:ciscomodel:jabberscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:virtualization experience media enginescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:jabberscope:lteversion:for windows 9.2.1

Trust: 0.8

vendor:ciscomodel:virtualization experience media enginescope:lteversion:9.2.1

Trust: 0.8

vendor:ciscomodel:virtualization experience media enginescope:eqversion:9.2.1

Trust: 0.3

vendor:ciscomodel:virtualization experience media enginescope:eqversion:9.0

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.2.1

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.2

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.1.5

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.1.4

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.1.3

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.1.2

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.1.1

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.1

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.0.5

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.0.4

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.0.3

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.0.2

Trust: 0.3

vendor:ciscomodel:jabber for windowsscope:eqversion:9.0.1

Trust: 0.3

sources: BID: 60764 // JVNDB: JVNDB-2013-003144 // CNNVD: CNNVD-201306-488 // NVD: CVE-2013-3393

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-3393
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-3393
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201306-488
value: MEDIUM

Trust: 0.6

VULHUB: VHN-63395
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-3393
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-63395
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-63395 // JVNDB: JVNDB-2013-003144 // CNNVD: CNNVD-201306-488 // NVD: CVE-2013-3393

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-63395 // JVNDB: JVNDB-2013-003144 // NVD: CVE-2013-3393

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201306-488

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201306-488

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-003144

PATCH

title:Cisco Jabber Video Engine Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3393

Trust: 0.8

title:29764url:http://tools.cisco.com/security/center/viewAlert.x?alertId=29764

Trust: 0.8

sources: JVNDB: JVNDB-2013-003144

EXTERNAL IDS

db:NVDid:CVE-2013-3393

Trust: 2.8

db:JVNDBid:JVNDB-2013-003144

Trust: 0.8

db:CNNVDid:CNNVD-201306-488

Trust: 0.7

db:CISCOid:20130625 CISCO JABBER VIDEO ENGINE DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:BIDid:60764

Trust: 0.4

db:VULHUBid:VHN-63395

Trust: 0.1

sources: VULHUB: VHN-63395 // BID: 60764 // JVNDB: JVNDB-2013-003144 // CNNVD: CNNVD-201306-488 // NVD: CVE-2013-3393

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2013-3393

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-3393

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-3393

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/web/products/voice/jabber.html

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps12862/index.html

Trust: 0.3

url:http://tools.cisco.com/security/center/viewalert.x?alertid=29764

Trust: 0.3

sources: VULHUB: VHN-63395 // BID: 60764 // JVNDB: JVNDB-2013-003144 // CNNVD: CNNVD-201306-488 // NVD: CVE-2013-3393

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 60764

SOURCES

db:VULHUBid:VHN-63395
db:BIDid:60764
db:JVNDBid:JVNDB-2013-003144
db:CNNVDid:CNNVD-201306-488
db:NVDid:CVE-2013-3393

LAST UPDATE DATE

2024-08-14T15:08:53.893000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-63395date:2013-08-31T00:00:00
db:BIDid:60764date:2013-06-25T00:00:00
db:JVNDBid:JVNDB-2013-003144date:2013-06-28T00:00:00
db:CNNVDid:CNNVD-201306-488date:2014-02-26T00:00:00
db:NVDid:CVE-2013-3393date:2013-08-31T06:39:14.203

SOURCES RELEASE DATE

db:VULHUBid:VHN-63395date:2013-06-26T00:00:00
db:BIDid:60764date:2013-06-25T00:00:00
db:JVNDBid:JVNDB-2013-003144date:2013-06-28T00:00:00
db:CNNVDid:CNNVD-201306-488date:2013-06-26T00:00:00
db:NVDid:CVE-2013-3393date:2013-06-26T19:55:01.133