CVE-2016-1400: Input Validation
Published May 25, 2016
·Updated
Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.
Affected Software
14 affected components
Cisco TelePresence Video Communication Server
Cisco TelePresence Video Communication Server=x8.1.1
Cisco TelePresence Video Communication Server=x8.1.2
Cisco TelePresence Video Communication Server=x8.1_base
Cisco TelePresence Video Communication Server=x8.2.1
Cisco TelePresence Video Communication Server=x8.2.2
Cisco TelePresence Video Communication Server=x8.2_base
Cisco TelePresence Video Communication Server=x8.5-rc4
Cisco TelePresence Video Communication Server=x8.5.0
Cisco TelePresence Video Communication Server=x8.5.1
Cisco TelePresence Video Communication Server=x8.5.2
Cisco TelePresence Video Communication Server=x8.5.3
Cisco TelePresence Video Communication Server=x8.6.0
Cisco TelePresence Video Communication Server=x8.6.1
Event History
May 25, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1400?
CVE-2016-1400 has a high severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2016-1400?
You can mitigate CVE-2016-1400 by upgrading to Cisco TelePresence Video Communication Server version X8.7.2 or later.
3
What does CVE-2016-1400 affect?
CVE-2016-1400 affects Cisco TelePresence Video Communication Server X8.x versions before X8.7.2.
4
What kind of attack does CVE-2016-1400 involve?
CVE-2016-1400 involves a denial of service attack executed through a crafted URI in a SIP header.
5
Is there a workaround for CVE-2016-1400?
There is no specific workaround for CVE-2016-1400; the recommended approach is to upgrade the affected software.