Vulnerability Details CVE-2015-0652
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.5%
CVSS Severity
CVSS v2 Score 7.8
Products affected by CVE-2015-0652
-
cpe:2.3:a:cisco:expressway_software:x7.2
-
cpe:2.3:a:cisco:expressway_software:x7.2.3
-
cpe:2.3:a:cisco:expressway_software:x7.2.4
-
cpe:2.3:a:cisco:expressway_software:x8.1
-
cpe:2.3:a:cisco:expressway_software:x8.1.1
-
cpe:2.3:a:cisco:telepresence_conductor:xc2.4
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x6.0
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x6.1
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x7.1
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x7.2
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x7.2.1
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x7.2.2
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x7.2.3
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x7.2.4
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x8.1
-
cpe:2.3:a:cisco:telepresence_video_communication_server_software:x8.1.1