Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2014-2171 | First vendor Publication | 2014-05-02 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2171 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2014-05-08 | IAVM : 2014-A-0067 - Multiple Vulnerabilities in Cisco Telepresence Products Severity : Category I - VMSKEY : V0050237 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-05-30 | Content-Type media type overflow denial of service attempt RuleID : 30890 - Revision : 3 - Type : PROTOCOL-VOIP |
2014-05-30 | Content-Type media type overflow denial of service attempt RuleID : 30889 - Revision : 3 - Type : PROTOCOL-VOIP |
2014-05-30 | Cisco Tshell command injection attempt RuleID : 30888 - Revision : 3 - Type : SERVER-OTHER |
2014-05-30 | Cisco Tshell command injection attempt RuleID : 30887 - Revision : 4 - Type : SERVER-OTHER |
2014-05-30 | Cisco SIP malformed date header buffer overflow attempt RuleID : 30886 - Revision : 4 - Type : PROTOCOL-VOIP |
2014-05-30 | Cisco SIP malformed date header buffer overflow attempt RuleID : 30885 - Revision : 4 - Type : PROTOCOL-VOIP |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-05-08 | Name : The remote host is missing a vendor-supplied security patch. File : cisco-sa-20140430-tcte.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 12:39:58 |
|
2021-05-04 12:30:55 |
|
2021-04-22 01:37:26 |
|
2020-05-23 00:40:27 |
|
2014-05-09 17:22:32 |
|
2014-05-09 13:25:57 |
|
2014-05-03 00:19:36 |
|
2014-05-02 17:21:18 |
|