CVE-2016-1338: Input Validation
Published Mar 12, 2016
·Updated
Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026.
Affected Software
2 affected components
Cisco Telepresence Video Communication Server Software=x8.5.1
Cisco Telepresence Video Communication Server Software=x8.5.2
Event History
Mar 12, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1338?
CVE-2016-1338 has a severity rating that indicates it can lead to a denial of service for VoIP services.
2
How do I fix CVE-2016-1338?
To fix CVE-2016-1338, upgrade to the latest version of Cisco TelePresence Video Communication Server firmware recommended by Cisco.
3
Which versions are vulnerable to CVE-2016-1338?
CVE-2016-1338 affects Cisco TelePresence Video Communication Server versions X8.5.1 and X8.5.2.
4
Who can exploit CVE-2016-1338?
CVE-2016-1338 can be exploited by remote authenticated users through a crafted SIP message.
5
What impact does CVE-2016-1338 have on the system?
The impact of CVE-2016-1338 is a denial of service which results in a disruptive VoIP outage.