ID

VAR-201502-0149


CVE

CVE-2015-0621


TITLE

Cisco TelePresence MCU Service disruption in device software (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-001547

DESCRIPTION

Cisco TelePresence MCU devices with software 4.5(1.45) allow remote attackers to cause a denial of service (device reload) via an unspecified series of TCP packets, aka Bug ID CSCur50347. Vendors have confirmed this vulnerability Bug ID CSCur50347 It is released as. Supplementary information : CWE Vulnerability type by CWE-19: Data Handling ( Data processing ) Has been identified. Cisco TelePresence Multipoint Control Unit is prone to a denial-of-service vulnerability. An attacker can exploit this issue to reload the device, denying service to legitimate users

Trust: 1.98

sources: NVD: CVE-2015-0621 // JVNDB: JVNDB-2015-001547 // BID: 72635 // VULHUB: VHN-78567

AFFECTED PRODUCTS

vendor:ciscomodel:telepresence mcu 4500 series softwarescope:eqversion:4.5\(1.45\)

Trust: 1.6

vendor:ciscomodel:telepresence mcu softwarescope:eqversion:4.5(1.45)

Trust: 0.8

sources: JVNDB: JVNDB-2015-001547 // CNNVD: CNNVD-201502-423 // NVD: CVE-2015-0621

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0621
value: HIGH

Trust: 1.0

NVD: CVE-2015-0621
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201502-423
value: HIGH

Trust: 0.6

VULHUB: VHN-78567
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-0621
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-78567
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-78567 // JVNDB: JVNDB-2015-001547 // CNNVD: CNNVD-201502-423 // NVD: CVE-2015-0621

PROBLEMTYPE DATA

problemtype:CWE-19

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-78567 // JVNDB: JVNDB-2015-001547 // NVD: CVE-2015-0621

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201502-423

TYPE

Unknown

Trust: 0.3

sources: BID: 72635

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001547

PATCH

title:Cisco TelePresence Multipoint Control Unit Denial of Service Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0621

Trust: 0.8

title:37495url:http://tools.cisco.com/security/center/viewAlert.x?alertId=37495

Trust: 0.8

sources: JVNDB: JVNDB-2015-001547

EXTERNAL IDS

db:NVDid:CVE-2015-0621

Trust: 2.8

db:BIDid:72635

Trust: 2.0

db:SECTRACKid:1031756

Trust: 1.7

db:JVNDBid:JVNDB-2015-001547

Trust: 0.8

db:CNNVDid:CNNVD-201502-423

Trust: 0.7

db:XFid:100936

Trust: 0.6

db:VULHUBid:VHN-78567

Trust: 0.1

sources: VULHUB: VHN-78567 // BID: 72635 // JVNDB: JVNDB-2015-001547 // CNNVD: CNNVD-201502-423 // NVD: CVE-2015-0621

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2015-0621

Trust: 2.0

url:http://www.securityfocus.com/bid/72635

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=37495

Trust: 1.7

url:http://www.securitytracker.com/id/1031756

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/100936

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0621

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0621

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/100936

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-78567 // BID: 72635 // JVNDB: JVNDB-2015-001547 // CNNVD: CNNVD-201502-423 // NVD: CVE-2015-0621

CREDITS

Cisco

Trust: 0.3

sources: BID: 72635

SOURCES

db:VULHUBid:VHN-78567
db:BIDid:72635
db:JVNDBid:JVNDB-2015-001547
db:CNNVDid:CNNVD-201502-423
db:NVDid:CVE-2015-0621

LAST UPDATE DATE

2024-11-23T23:12:43.824000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-78567date:2017-09-08T00:00:00
db:BIDid:72635date:2015-02-17T00:00:00
db:JVNDBid:JVNDB-2015-001547date:2015-02-23T00:00:00
db:CNNVDid:CNNVD-201502-423date:2015-02-26T00:00:00
db:NVDid:CVE-2015-0621date:2024-11-21T02:23:25.563

SOURCES RELEASE DATE

db:VULHUBid:VHN-78567date:2015-02-18T00:00:00
db:BIDid:72635date:2015-02-17T00:00:00
db:JVNDBid:JVNDB-2015-001547date:2015-02-23T00:00:00
db:CNNVDid:CNNVD-201502-423date:2015-02-26T00:00:00
db:NVDid:CVE-2015-0621date:2015-02-18T02:59:04.737