VendorsCiscomeeting_serverany version
Vulnerabilities

Cisco Meeting Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2017-12249
A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system. The vulnerability is due to an incorrect default configuration of the TURN server, which could expose internal interfaces and ports on the external interface of an affected system. An attacker could exploit this vulnerability by using a TURN server to perform an unauthorized connection to a Call Bridge, a Web Bridge, or a database cluster in an affected system, depending on the deployment model and CMS services in use. A successful exploit could allow the attacker to gain unauthenticated access to a Call Bridge or database cluster in an affected system or gain unauthorized access to sensitive meeting information in an affected system. To exploit this vulnerability, the attacker must have valid credentials for the TURN server of the affected system. This vulnerability affects Cisco Meeting Server (CMS) deployments that are running a CMS Software release prior to Release 2.0.16, 2.1.11, or 2.2.6. Cisco Bug IDs: CSCvf51127.
Published 2017-09-13 · Modified
9.1EPSS 0.031
CVE-2017-12362
A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems with a particular configuration. An attacker could exploit this by knowing a valid URI that directs to a Cisco Meeting Server. An attacker could then make a video call and cause the system to reload. Cisco Bug IDs: CSCve65931.
Published 2017-11-30 · Modified
7.8EPSS 0.023
CVE-2018-15446
Cisco Meeting Server Information Disclosure Vulnerability
Published 2018-11-08 · Modified
7.5EPSS 0.022
CVE-2019-1676
Cisco Meeting Server SIP Processing Denial of Service Vulnerability
Published 2019-02-08 · Modified
7.5EPSS 0.018
CVE-2021-40122
Cisco Meeting Server Call Bridge Denial of Service Vulnerability
Published 2021-10-21 · Modified
7.5EPSS 0.012
CVE-2018-0263
A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of the device, which can expose internal interfaces and ports on the external interface of the system. A successful exploit could allow the attacker to gain unauthenticated access to configuration and database files and sensitive meeting information on an affected system. This vulnerability affects Cisco Meeting Server (CMS) 2000 Platforms that are running a CMS Software release prior to Release 2.2.13 or Release 2.3.4. Cisco Bug IDs: CSCvg76471.
Published 2018-06-07 · Modified
7.4EPSS 0.007
CVE-2019-1623
Cisco Meeting Server CLI Command Injection Vulnerability
Published 2019-06-20 · Modified
7.2EPSS 0.005
CVE-2017-12224
A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due to the incorrect implementation of the configuration setting Guest access via hyperlinks, which should allow the administrative user to prevent guest users from using hyperlinks to connect to meetings. An attacker could exploit this vulnerability by using a crafted hyperlink to connect to a meeting. An exploit could allow the attacker to connect directly to the meeting with a hyperlink, even though access should be denied. The attacker would still require a valid hyperlink and encoded secret identifier to be connected. Cisco Bug IDs: CSCve20873.
Published 2017-09-07 · Modified
6.5EPSS 0.015
CVE-2021-1524
Cisco Meeting Server API Denial of Service Vulnerability
Published 2021-06-16 · Modified
6.5EPSS 0.011
CVE-2017-12264
A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient bound checks performed by the affected software. An attacker could exploit this vulnerability by sending a malicious HTTP packet to the affected system. A successful exploit could allow the attacker to cause a reload of the Web Admin Server. Cisco Bug IDs: CSCve89149.
Published 2017-10-05 · Modified
5.3EPSS 0.022
CVE-2020-3160
Cisco Meeting Server Extensible Messaging and Presence Protocol Denial of Service Vulnerability
Published 2020-02-19 · Modified
5.3EPSS 0.012
CVE-2020-3197
Cisco Meetings App Missing TURN Server Credentials Expiration Vulnerability
Published 2020-07-16 · Modified
5.3EPSS 0.010
CVE-2023-20255
A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP packets to an affected device. A successful exploit could allow the attacker to cause a partial availability condition, which could cause ongoing video calls to be dropped due to the invalid packets reaching the Web Bridge.
Published 2023-11-01 · Modified
5.3EPSS 0.008