Cisco-SA-20150217-CVE-2015-0621

Cisco TelePresence Multipoint Control Unit Denial of Service Vulnerability

Medium · Updated · Cisco

1 product with CSAF evidence

A vulnerability in the Cisco TelePresence multipoint control unit (MCU) could allow an unauthenticated, remote attacker to trigger a reload of an affected system. The vulnerability is due to insufficient sanitization of TCP packets. An attacker could exploit this vulnerability by sending a sequence of TCP packets to the affected system. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send a sequence of TCP packets to the targeted system. This access requirement may reduce the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.