CVE-2012-3073

UnknownEPSS 1.80%

Last modified

CVE-2012-3073 is a vulnerability of currently unknown severity. The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.. EPSS estimates a 1.80% chance of exploitation in the next 30 days.

Description

The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.

Metrics

EPSS Probability
1.80%

75.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoTelepresence Multipoint Switch Software<= 1.8.0\(1026\)
CiscoTelepresence Multipoint Switch Software1.0.4.0
CiscoTelepresence Multipoint Switch Software1.0.4.0\(21\)
CiscoTelepresence Multipoint Switch Software1.1.0
CiscoTelepresence Multipoint Switch Software1.1.0\(254\)
CiscoTelepresence Multipoint Switch Software1.1.1
CiscoTelepresence Multipoint Switch Software1.1.1\(30\)
CiscoTelepresence Multipoint Switch Software1.1.2
CiscoTelepresence Multipoint Switch Software1.1.2\(6\)
CiscoTelepresence Multipoint Switch Software1.5.0
CiscoTelepresence Multipoint Switch Software1.5.0\(222\)
CiscoTelepresence Multipoint Switch Software1.5.1
CiscoTelepresence Multipoint Switch Software1.5.1\(2\)
CiscoTelepresence Multipoint Switch Software1.5.2
CiscoTelepresence Multipoint Switch Software1.5.2\(21\)
CiscoTelepresence Multipoint Switch Software1.5.3
CiscoTelepresence Multipoint Switch Software1.5.3.12
CiscoTelepresence Multipoint Switch Software1.5.4
CiscoTelepresence Multipoint Switch Software1.5.4\(4\)
CiscoTelepresence Multipoint Switch Software1.5.5
CiscoTelepresence Multipoint Switch Software1.5.5\(1\)
CiscoTelepresence Multipoint Switch Software1.5.6
CiscoTelepresence Multipoint Switch Software1.5.6\(1\)
CiscoTelepresence Multipoint Switch Software1.6.0
CiscoTelepresence Multipoint Switch Software1.6.0\(108\)
CiscoTelepresence Multipoint Switch Software1.6.1
CiscoTelepresence Multipoint Switch Software1.6.1\(2\)
CiscoTelepresence Multipoint Switch Software1.6.2
CiscoTelepresence Multipoint Switch Software1.6.2\(3\)
CiscoTelepresence Multipoint Switch Software1.6.3
CiscoTelepresence Multipoint Switch Software1.6.3\(2\)
CiscoTelepresence Multipoint Switch Software1.6.4
CiscoTelepresence Multipoint Switch Software1.6.4\(3\)
CiscoTelepresence Multipoint Switch Software1.7.0
CiscoTelepresence Multipoint Switch Software1.7.0.1\(5\)
CiscoTelepresence Multipoint Switch Software1.7.1\(15\)
CiscoTelepresence Multipoint Switch Software1.7.2\(75\)
CiscoTelepresence Multipoint Switch Software1.7.3\(2\)
CiscoTelepresence Multipoint Switch Software1.8.0
CiscoTelepresence Multipoint SwitchAll versions
CiscoTelepresence System Software<= 1.9.0.1\(3\)
CiscoTelepresence System Software1.2.3\(1101\)
CiscoTelepresence System Software1.3.2\(1393\)
CiscoTelepresence System Software1.4.7\(2229\)
CiscoTelepresence System Software1.5.1\(2082\)
CiscoTelepresence System Software1.5.3\(2115\)
CiscoTelepresence System Software1.5.10\(3648\)
CiscoTelepresence System Software1.5.11\(3659\)
CiscoTelepresence System Software1.5.12\(3701\)
CiscoTelepresence System Software1.5.13\(3717\)

Showing 50 of 108 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-3073?
The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.
How severe is CVE-2012-3073?
Severity scoring for CVE-2012-3073 is pending analysis. The EPSS model estimates a 1.80% probability of exploitation in the next 30 days.
How do I fix CVE-2012-3073?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-3073?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST