CVE-2016-6447
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to 2.0.1, Acano Server releases prior to 1.8.16 and prior to 1.9.3, Cisco Meeting App releases prior to 1.9.8, Acano Meeting Apps releases prior to 1.8.35. More Information: CSCva75942 CSCvb67878. Known Affected Releases: 1.81.92.0.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | meeting_app | 1.8.0 | |
| cisco | meeting_app | 1.9.0 | |
| cisco | meeting_server | 1.8_base | |
| cisco | meeting_server | 1.9.0 | |
| cisco | meeting_server | 2.0.0 | |
References
- http://www.securityfocus.com/bid/94073
- http://www.securitytracker.com/id/1037180
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms
- http://www.securityfocus.com/bid/94073
- http://www.securitytracker.com/id/1037180
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.