HIGH · 7.5

CVE-2015-6360

The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.

Vulnerability Description

The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos Xe3.10s_3.10.0s
CiscoWebex Meeting Centerbase
CiscoDx Series Ip Phones Firmware9.3\(2\)
CiscoIp Phone 7800 Series Firmware10.3\(1\)
CiscoIp Phone 8800 Series Firmware10.3\(2\)
CiscoUnified Ip Phone 6900 Series Firmware9.3\(2\)
CiscoUnified Ip Phone 7900 Series Firmware9.9\(9.99001.1\)
CiscoUnified Ip Phone 8900 Series Firmware9.0\(1\)sr1
CiscoUnified Wireless Ip Phone 7920 Firmware1.0\(5\)
CiscoAdaptive Security Appliance Software8.1.0.104
CiscoUnity Connection1.1\(1\)
CiscoJabber Software Development Kit8.6\(1\)
CiscoLibsrtp<= 1.5.2
CiscoUnified Communications Manager9.9\(9\)st1.9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-6360?

CVE-2015-6360 is a vulnerability with a CVSS score of 7.5 (HIGH). The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.

How severe is CVE-2015-6360?

CVE-2015-6360 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-6360?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco Webex Meeting Center, Cisco Dx Series Ip Phones Firmware, Cisco Ip Phone 7800 Series Firmware, Cisco Ip Phone 8800 Series Firmware.