Cisco
Cisco Meeting Server: vulnerabilidades y CVE
Cisco Meeting Server tiene 31 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20255 | Media (5.3) | 0.81% | — | 1 nov 2023 | A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient… |
| CVE-2021-40122 | Alta (7.5) | 1.2% | — | 21 oct 2021 | A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling… |
| CVE-2021-1524 | Media (6.5) | 1.1% | — | 16 jun 2021 | A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are… |
| CVE-2020-3197 | Media (5.3) | 0.99% | — | 16 jul 2020 | A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected… |
| CVE-2020-3160 | Media (5.3) | 1.2% | — | 19 feb 2020 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of… |
| CVE-2019-1623 | Media (6.7) | 0.51% | — | 20 jun 2019 | A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input… |
| CVE-2019-1794 | Media (5.1) | 0.38% | — | 18 abr 2019 | A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements.… |
| CVE-2019-1676 | Alta (7.5) | 1.8% | — | 8 feb 2019 | A vulnerability in the Session Initiation Protocol (SIP) call processing of Cisco Meeting Server (CMS) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Cisco… |
| CVE-2019-1678 | Media (4.3) | 1.4% | — | 7 feb 2019 | A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol… |
| CVE-2018-15446 | Alta (7.5) | 2.2% | — | 8 nov 2018 | A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper protections on data that is returned from user… |
| CVE-2018-0439 | Alta (8.8) | 1.2% | — | 5 oct 2018 | A vulnerability in the web-based management interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an… |
| CVE-2018-0371 | Media (6.5) | 2.8% | — | 21 jun 2018 | A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of… |
| CVE-2018-0359 | Media (5.5) | 0.36% | — | 21 jun 2018 | A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid user session… |
| CVE-2018-0263 | Alta (7.4) | 0.74% | — | 7 jun 2018 | A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect… |
| CVE-2018-0280 | Alta (7.5) | 3.3% | — | 17 may 2018 | A vulnerability in the Real-Time Transport Protocol (RTP) bitstream processing of the Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability… |
| CVE-2018-0262 | Alta (8.1) | 4.0% | — | 2 may 2018 | A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution.… |
| CVE-2017-12362 | Media (6.5) | 2.3% | — | 30 nov 2017 | A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to… |
| CVE-2017-12311 | Media (5.8) | 2.2% | — | 16 nov 2017 | A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server media process to restart unexpectedly when it receives an illegal… |
| CVE-2017-12264 | Media (5.3) | 2.2% | — | 5 oct 2017 | A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient bound checks… |
| CVE-2017-12249 | Crítica (9.1) | 3.1% | — | 13 sept 2017 | A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or… |
| CVE-2017-6794 | Media (6.7) | 0.84% | — | 7 sept 2017 | A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first… |
| CVE-2017-12224 | Media (6.5) | 1.5% | — | 7 sept 2017 | A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should… |
| CVE-2017-6763 | Alta (7.5) | 2.3% | — | 7 ago 2017 | A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The… |
| CVE-2017-3837 | Alta (8.1) | 2.1% | — | 22 feb 2017 | An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which… |
| CVE-2017-3830 | Alta (7.5) | 2.6% | — | 22 feb 2017 | A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected appliance. More Information: CSCvc89678.… |
| CVE-2016-6448 | Crítica (9.8) | 4.0% | — | 3 nov 2016 | A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the… |
| CVE-2016-6447 | Crítica (9.8) | 3.1% | — | 3 nov 2016 | A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting… |
| CVE-2016-6446 | Alta (7.5) | 1.4% | — | 27 oct 2016 | A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. |
| CVE-2016-6445 | Crítica (9.1) | 2.5% | — | 27 oct 2016 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated,… |
| CVE-2016-6444 | Alta (8.8) | 0.56% | — | 27 oct 2016 | A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.