CVE-2016-9224: Input Validation
Published Dec 26, 2016
·Updated
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0).
Affected Software
5 affected components
Cisco Jabber Guest=10.0.0
Cisco Jabber Guest=10.0.2
Cisco Jabber Guest=10.5.0
Cisco Jabber Guest=10.6.8
Cisco Jabber Guest=10.6.9
Event History
Dec 26, 2016
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9224?
CVE-2016-9224 is classified as a high severity vulnerability due to its potential to allow unauthenticated remote access.
2
How do I fix CVE-2016-9224?
To fix CVE-2016-9224, you should upgrade Cisco Jabber Guest to a fixed release, such as version 11.0(0) or later.
3
Which versions of Cisco Jabber are affected by CVE-2016-9224?
CVE-2016-9224 affects Cisco Jabber Guest versions 10.0.0, 10.0.2, 10.5.0, 10.6.8, and 10.6.9.
4
Can CVE-2016-9224 be exploited by authenticated users?
No, CVE-2016-9224 can be exploited by unauthenticated users, making it more critical.
5
What does CVE-2016-9224 allow an attacker to do?
CVE-2016-9224 allows an unauthenticated attacker to initiate connections to arbitrary hosts.