CVE-2015-6360
UnknownEPSS 8.28%
Last modified
CVE-2015-6360 is a vulnerability of currently unknown severity. The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.. EPSS estimates a 8.28% chance of exploitation in the next 30 days.
Description
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.10s_3.10.0s |
| Cisco | Ios Xe | 3.10s_3.10.1s |
| Cisco | Ios Xe | 3.10s_3.10.1xbs |
| Cisco | Ios Xe | 3.10s_3.10.2s |
| Cisco | Ios Xe | 3.10s_3.10.2ts |
| Cisco | Ios Xe | 3.10s_3.10.4s |
| Cisco | Ios Xe | 3.10s_3.10.5s |
| Cisco | Ios Xe | 3.10s_3.10.6s |
| Cisco | Ios Xe | 3.10s_3.10.7s |
| Cisco | Ios Xe | 3.11s_3.11.0s |
| Cisco | Ios Xe | 3.11s_3.11.1s |
| Cisco | Ios Xe | 3.11s_3.11.2s |
| Cisco | Ios Xe | 3.11s_3.11.3s |
| Cisco | Ios Xe | 3.11s_3.11.4s |
| Cisco | Ios Xe | 3.13s_3.13.0s |
| Cisco | Ios Xe | 3.13s_3.13.1s |
| Cisco | Ios Xe | 3.13s_3.13.4s |
| Cisco | Ios Xe | 3.14s_3.14.0s |
| Cisco | Ios Xe | 3.15s_3.15.1s |
| Cisco | Ios Xe | 3.15s_3.15.2s |
| Cisco | Webex Meeting Center | base |
| Cisco | Dx Series Ip Phones Firmware | 9.3\(2\) |
| Cisco | Ip Phone 7800 Series Firmware | 10.3\(1\) |
| Cisco | Ip Phone 8800 Series Firmware | 10.3\(2\) |
| Cisco | Ip Phone 8800 Series Firmware | 11.0\(1\) |
| Cisco | Unified Ip Phone 6900 Series Firmware | 9.3\(2\) |
| Cisco | Unified Ip Phone 7900 Series Firmware | 9.9\(9.99001.1\) |
| Cisco | Unified Ip Phone 7900 Series Firmware | 9.9_base |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.0\(1\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.0\(3\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.0\(4\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.1\(1\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.1\(2\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(1\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(2\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(2\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(3\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(4\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(1\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(2\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(2\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(4\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.4\(1\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.4\(1\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.4\(2\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(5\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(6\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(7\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(8\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(9\) |
Showing 50 of 291 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6360?
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
How severe is CVE-2015-6360?
Severity scoring for CVE-2015-6360 is pending analysis. The EPSS model estimates a 8.28% probability of exploitation in the next 30 days.
How do I fix CVE-2015-6360?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-6354Multiple cross-site scripting (XSS) vulnerabilities in Cisco…
- CVE-2015-6355The web interface in Cisco Unified Computing System (UCS) 2.…
- CVE-2015-6356Cross-site scripting (XSS) vulnerability in the WeChat page …
- CVE-2015-6357The rule-update feature in Cisco FireSIGHT Management Center…
- CVE-2015-6358Multiple Cisco embedded devices use hardcoded X.509 certific…
- CVE-2015-6359The Neighbor Discovery (ND) protocol implementation in the I…
- CVE-2015-6361The administrative web interface on Cisco DPC3939 (XB3) devi…
- CVE-2015-6362The web GUI in Cisco Connected Grid Network Management Syste…
- CVE-2015-6363Multiple cross-site scripting (XSS) vulnerabilities in the w…
- CVE-2015-6364Cisco Content Delivery System Manager Software 3.2 on Videos…
- CVE-2015-6365Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface AC…
- CVE-2015-6366Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface A…
Are you affected by CVE-2015-6360?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
