Vulnslist

find the latest Cisco vulnerabilities

Cisco TelePresence MCU Software Memory Exhaustion Vulnerability

cisco-sa-20141015-mcu · High · Published · Updated

A vulnerability in the network stack of Cisco TelePresence MCU Software could allow an unauthenticated, remote attacker to cause the exhaustion of available memory which could lead to system instability and a reload of the affected system. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141015-mcu Note: This security advisory does not provide information about the GNU Bash Environment Variable Command Injection Vulnerability (also known as Shellshock). For additional information regarding Cisco products affected by this vulnerability, refer to the Cisco Security Advisory at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that mitigate this vulnerability

CVEsCVE-2014-3397
Cisco Bug IDsCSCtz35468
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:H/RL:OF/RC:C
Product Names From Source
Cisco TelePresence MCU Software

Related Products

Product CVE Evidence
Cisco TelePresence MCU Software CVE-2014-3397 Cisco OpenVuln
Cisco TelePresence CVE-2014-3397 Cisco OpenVuln