Vulnslist

find the latest Cisco vulnerabilities

Cisco Expressway Series Software Security Bypass Vulnerability

cisco-sa-20161207-expressway · Medium · Published · Updated

A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. The vulnerability is due to insufficient access control for TCP traffic passed through the Cisco Expressway. An attacker could exploit this vulnerability by sending a crafted URL through the Cisco Expressway. An exploit could allow the attacker to enumerate hosts and services of arbitrary hosts, as well as degrade performance through the Cisco Expressway. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-expressway

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-9207
Cisco Bug IDsCSCvc10834
CVSS ScoreBase 6.4
Base 6.4 AV:N/AC:L/Au:N/C:P/I:N/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco TelePresence Video Communication Server (VCS), Cisco Expressway

Related Products

Product CVE Evidence
Cisco TelePresence Video Communication Server (VCS) CVE-2016-9207 Cisco OpenVuln
Cisco TelePresence CVE-2016-9207 Cisco OpenVuln
Cisco Expressway CVE-2016-9207 Cisco OpenVuln