cisco-sa-meetingserver-dos-NzVWMMQT: Cisco Meeting Server API Denial of Service Vulnerability
A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. An attacker could exploit this vulnerability by sending a malicious request to the API. A successful exploit could allow the attacker to cause all participants on a call to be disconnected, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meetingserver-dos-NzVWMMQT
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-meetingserver-dos-NzVWMMQT?
The cisco-sa-meetingserver-dos-NzVWMMQT vulnerability is classified as a denial of service (DoS) vulnerability affecting Cisco Meeting Server.
How do I fix cisco-sa-meetingserver-dos-NzVWMMQT?
To fix the cisco-sa-meetingserver-dos-NzVWMMQT vulnerability, update to the latest version of Cisco Meeting Server as recommended by Cisco.
What kind of attack does cisco-sa-meetingserver-dos-NzVWMMQT allow?
The cisco-sa-meetingserver-dos-NzVWMMQT vulnerability allows an authenticated, remote attacker to cause a denial of service condition on affected devices.
What conditions are necessary to exploit cisco-sa-meetingserver-dos-NzVWMMQT?
Exploiting the cisco-sa-meetingserver-dos-NzVWMMQT vulnerability requires an attacker to be authenticated and to send unvalidated requests to the API.
Which product is affected by cisco-sa-meetingserver-dos-NzVWMMQT?
The cisco-sa-meetingserver-dos-NzVWMMQT vulnerability specifically affects Cisco Meeting Server.