7.8

CVE-2015-6360

The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Xe Version3.10s_3.10.0s
CiscoIos Xe Version3.10s_3.10.1s
CiscoIos Xe Version3.10s_3.10.1xbs
CiscoIos Xe Version3.10s_3.10.2s
CiscoIos Xe Version3.10s_3.10.2ts
CiscoIos Xe Version3.10s_3.10.4s
CiscoIos Xe Version3.10s_3.10.5s
CiscoIos Xe Version3.10s_3.10.6s
CiscoIos Xe Version3.10s_3.10.7s
CiscoIos Xe Version3.11s_3.11.0s
CiscoIos Xe Version3.11s_3.11.1s
CiscoIos Xe Version3.11s_3.11.2s
CiscoIos Xe Version3.11s_3.11.3s
CiscoIos Xe Version3.11s_3.11.4s
CiscoIos Xe Version3.13s_3.13.0s
CiscoIos Xe Version3.13s_3.13.1s
CiscoIos Xe Version3.13s_3.13.4s
CiscoIos Xe Version3.14s_3.14.0s
CiscoIos Xe Version3.15s_3.15.1s
CiscoIos Xe Version3.15s_3.15.2s
CiscoWebex Meeting Center Versionbase
CiscoUnity Connection Version1.2_base
CiscoUnity Connection Version2.0_base
CiscoUnity Connection Version2.1_base
CiscoUnity Connection Version7.0_base
CiscoUnity Connection Version7.1.5es33.32900-33
CiscoUnity Connection Version7.1_base
CiscoUnity Connection Version8.0_base
CiscoUnity Connection Version8.5_base
CiscoUnity Connection Version8.6_base
CiscoUnity Connection Version10.0.0
CiscoUnity Connection Version10.0.5
CiscoUnity Connection Version10.5_base
CiscoUnity Connection Version11.0_0
CiscoUnity Connection Version11.5_base
CiscoLibsrtp Version <= 1.5.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 17.94% 0.949
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.