CVE-2020-3596
Cisco Expressway Series and TelePresence Video Communication Server Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect handling of incoming SIP traffic. An attacker could exploit this vulnerability by sending a series of SIP packets to an affected device. A successful exploit could allow the attacker to exhaust memory on an affected device, causing it to crash and leading to a DoS condition.
Una vulnerabilidad en el Session Initiation Protocol (SIP) de Cisco Expressway Series y Cisco TelePresence Video Communication Server (VCS), podría permitir a un atacante remoto no autenticado causar una condición de denegación de servicio (DoS) en un dispositivo afectado. La vulnerabilidad es debido al manejo incorrecto del tráfico SIP entrante. Un atacante podría explotar esta vulnerabilidad mediante el envío de una serie de paquetes SIP hacia un dispositivo afectado. Una explotación con éxito podría permitir que el atacante agote la memoria de un dispositivo afectado, causando que se bloquee y conllevando a una condición DoS
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-12-12 CVE Reserved
- 2020-10-08 CVE Published
- 2023-06-24 EPSS Updated
- 2024-11-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-670: Always-Incorrect Control Flow Implementation
- CWE-789: Memory Allocation with Excessive Size Value
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Expressway Search vendor "Cisco" for product "Expressway" | <= x12.6.3 Search vendor "Cisco" for product "Expressway" and version " <= x12.6.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | <= x12.6.3 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version " <= x12.6.3" | - |
Affected
|