imPC@ndo IT

Tracker / CVE-2015-6360

CVE-2015-6360

High 7.5

The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.

Affected products and versions

cisco adaptive_security_appliance_software
cisco dx_series_ip_phones_firmware
cisco ios_xe
cisco ip_phone_7800_series_firmware
cisco ip_phone_8800_series_firmware
cisco jabber_software_development_kit
cisco libsrtp · … → 1.5.2
cisco unified_communications_manager
cisco unified_ip_phone_6900_series_firmware
cisco unified_ip_phone_7900_series_firmware
cisco unified_ip_phone_8900_series_firmware
cisco unified_wireless_ip_phone_7920_firmware
cisco unity_connection
cisco webex_meeting_center

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References