CVE-2016-6446: Infoleak
Published Oct 27, 2016
·Updated
A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0.
Affected Software
9 affected components
Cisco Meeting Server=1.8.15
Cisco Meeting Server=1.8_base
Cisco Meeting Server=1.9.0
Cisco Meeting Server=1.9.2
Cisco Meeting Server=2.0.0
Cisco Meeting Server=2.0.1
Cisco Meeting Server=2.0.3
Cisco Meeting Server=2.0.4
Cisco Meeting Server=2.0.5
Event History
Oct 27, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-6446?
CVE-2016-6446 has a high severity rating due to its potential to allow unauthorized access to sensitive memory data.
2
How do I fix CVE-2016-6446?
To fix CVE-2016-6446, update your Cisco Meeting Server to a patched version that addresses this vulnerability.
3
Who is affected by CVE-2016-6446?
CVE-2016-6446 affects users of Cisco Meeting Server versions 1.8, 1.9, and 2.0.
4
What is the impact of CVE-2016-6446?
The impact of CVE-2016-6446 includes the possibility for an unauthenticated attacker to retrieve sensitive memory information.
5
Is there a workaround for CVE-2016-6446?
Currently, there are no effective workarounds for CVE-2016-6446; therefore, patching is essential.