Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40122

Опубликовано: 21 окт. 2021
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An attacker could exploit this vulnerability by sending a series of messages to the vulnerable API. A successful exploit could allow the attacker to cause the affected device to reload, dropping all ongoing calls and resulting in a DoS condition.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:meeting_server:*:*:*:*:*:*:*:*
Версия до 3.1 (включая)
cpe:2.3:a:cisco:meeting_server:*:*:*:*:*:*:*:*
Версия от 3.2 (включая) до 3.2.3 (исключая)

EPSS

Процентиль: 59%
0.00376
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-399
CWE-404

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An attacker could exploit this vulnerability by sending a series of messages to the vulnerable API. A successful exploit could allow the attacker to cause the affected device to reload, dropping all ongoing calls and resulting in a DoS condition.

CVSS3: 5.9
fstec
больше 4 лет назад

Уязвимость программного интерфейса платформы для проведения конференций Cisco Meeting Server, позволяющая нарушителю вызвать отказ в обслуживании или вызвать перезагрузку устройства

EPSS

Процентиль: 59%
0.00376
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-399
CWE-404