CVE-2014-3397: High severity cisco telepresence mcu software vulnerability
The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets, aka Bug ID CSCtz35468.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3397?
CVE-2014-3397 has a medium severity rating due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2014-3397?
To fix CVE-2014-3397, update Cisco TelePresence MCU Software to version 4.3(2.30) or later.
What is the impact of CVE-2014-3397?
The impact of CVE-2014-3397 is that remote attackers can exploit it to consume memory and create a denial-of-service condition.
Which versions of Cisco TelePresence MCU Software are vulnerable to CVE-2014-3397?
Cisco TelePresence MCU Software versions prior to 4.3(2.30), specifically up to and including 4.3(2.18), are vulnerable to CVE-2014-3397.
Are there any workarounds for CVE-2014-3397?
There are no known workarounds for CVE-2014-3397 and applying the security update is recommended.