First published: Thu Nov 03 2016(Updated: )
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Meeting Server | =1.8.15 | |
Cisco Meeting Server | =1.8_base | |
Cisco Meeting Server | =1.9.0 | |
Cisco Meeting Server | =1.9.2 | |
Cisco Meeting Server | =2.0.0 | |
Cisco Meeting Server | =2.0.1 | |
Cisco Meeting Server | =2.0.3 | |
Cisco Meeting Server | =2.0.4 | |
Cisco Meeting Server | =2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6448 is rated as critical due to its potential for remote arbitrary code execution.
To mitigate CVE-2016-6448, upgrade the Cisco Meeting Server to at least Release 2.0.3.
CVE-2016-6448 impacts Cisco Meeting Server versions 1.8.15, 1.8_base, 1.9.0, 1.9.2, 2.0.0, 2.0.1, and 2.0.2.
An attacker can exploit CVE-2016-6448 by sending specially crafted Session Description Protocol (SDP) messages to execute arbitrary code.
No, CVE-2016-6448 can be exploited by an unauthenticated remote attacker.