ID

VAR-201506-0164


CVE

CVE-2015-0772


TITLE

Cisco TelePresence Video Communication Server Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-003074

DESCRIPTION

Cisco TelePresence Video Communication Server (VCS) X8.5RC4 allows remote attackers to cause a denial of service (CPU consumption or device outage) via a crafted SDP parameter-negotiation request in an SDP session during a SIP connection, aka Bug ID CSCut42422. An attacker can exploit this issue to cause a denial of service condition, denying service to legitimate users. This issue is being tracked by Cisco bug ID CSCut42422

Trust: 2.07

sources: NVD: CVE-2015-0772 // JVNDB: JVNDB-2015-003074 // BID: 75101 // VULHUB: VHN-78718 // VULMON: CVE-2015-0772

AFFECTED PRODUCTS

vendor:ciscomodel:telepresence video communication server softwarescope:eqversion:x8.5

Trust: 1.6

vendor:ciscomodel:telepresence video communication serverscope: - version: -

Trust: 0.8

vendor:ciscomodel:telepresence video communication server softwarescope:eqversion:x8.5rc4

Trust: 0.8

vendor:ciscomodel:telepresence video communication server rc4scope:eqversion:x8.5

Trust: 0.3

sources: BID: 75101 // JVNDB: JVNDB-2015-003074 // CNNVD: CNNVD-201506-239 // NVD: CVE-2015-0772

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0772
value: HIGH

Trust: 1.0

NVD: CVE-2015-0772
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201506-239
value: HIGH

Trust: 0.6

VULHUB: VHN-78718
value: HIGH

Trust: 0.1

VULMON: CVE-2015-0772
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-0772
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-78718
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-78718 // VULMON: CVE-2015-0772 // JVNDB: JVNDB-2015-003074 // CNNVD: CNNVD-201506-239 // NVD: CVE-2015-0772

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-78718 // JVNDB: JVNDB-2015-003074 // NVD: CVE-2015-0772

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201506-239

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201506-239

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003074

PATCH

title:39240url:http://tools.cisco.com/security/center/viewAlert.x?alertId=39240

Trust: 0.8

title:Cisco: Cisco TelePresence Video Communication Server SDP Over SIP Denial of Service Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=cisco_security_advisories_and_alerts_ciscoproducts&qid=Cisco-SA-20150609-CVE-2015-0772

Trust: 0.1

sources: VULMON: CVE-2015-0772 // JVNDB: JVNDB-2015-003074

EXTERNAL IDS

db:NVDid:CVE-2015-0772

Trust: 2.9

db:SECTRACKid:1032540

Trust: 1.2

db:JVNDBid:JVNDB-2015-003074

Trust: 0.8

db:CNNVDid:CNNVD-201506-239

Trust: 0.7

db:BIDid:75101

Trust: 0.4

db:VULHUBid:VHN-78718

Trust: 0.1

db:VULMONid:CVE-2015-0772

Trust: 0.1

sources: VULHUB: VHN-78718 // VULMON: CVE-2015-0772 // BID: 75101 // JVNDB: JVNDB-2015-003074 // CNNVD: CNNVD-201506-239 // NVD: CVE-2015-0772

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=39240

Trust: 2.1

url:http://www.securitytracker.com/id/1032540

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0772

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0772

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20150609-cve-2015-0772

Trust: 0.1

sources: VULHUB: VHN-78718 // VULMON: CVE-2015-0772 // BID: 75101 // JVNDB: JVNDB-2015-003074 // CNNVD: CNNVD-201506-239 // NVD: CVE-2015-0772

CREDITS

Cisco

Trust: 0.3

sources: BID: 75101

SOURCES

db:VULHUBid:VHN-78718
db:VULMONid:CVE-2015-0772
db:BIDid:75101
db:JVNDBid:JVNDB-2015-003074
db:CNNVDid:CNNVD-201506-239
db:NVDid:CVE-2015-0772

LAST UPDATE DATE

2024-11-23T22:18:23.995000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-78718date:2017-01-04T00:00:00
db:VULMONid:CVE-2015-0772date:2017-01-04T00:00:00
db:BIDid:75101date:2015-06-09T00:00:00
db:JVNDBid:JVNDB-2015-003074date:2015-06-16T00:00:00
db:CNNVDid:CNNVD-201506-239date:2015-06-18T00:00:00
db:NVDid:CVE-2015-0772date:2024-11-21T02:23:41.433

SOURCES RELEASE DATE

db:VULHUBid:VHN-78718date:2015-06-12T00:00:00
db:VULMONid:CVE-2015-0772date:2015-06-12T00:00:00
db:BIDid:75101date:2015-06-09T00:00:00
db:JVNDBid:JVNDB-2015-003074date:2015-06-16T00:00:00
db:CNNVDid:CNNVD-201506-239date:2015-06-15T00:00:00
db:NVDid:CVE-2015-0772date:2015-06-12T14:59:01.957