CVE-2015-6360
UnknownEPSS 8.28%
Last modified
CVE-2015-6360 is a vulnerability of currently unknown severity. The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.. EPSS estimates a 8.28% chance of exploitation in the next 30 days.
Description
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.10s_3.10.0s |
| Cisco | Ios Xe | 3.10s_3.10.1s |
| Cisco | Ios Xe | 3.10s_3.10.1xbs |
| Cisco | Ios Xe | 3.10s_3.10.2s |
| Cisco | Ios Xe | 3.10s_3.10.2ts |
| Cisco | Ios Xe | 3.10s_3.10.4s |
| Cisco | Ios Xe | 3.10s_3.10.5s |
| Cisco | Ios Xe | 3.10s_3.10.6s |
| Cisco | Ios Xe | 3.10s_3.10.7s |
| Cisco | Ios Xe | 3.11s_3.11.0s |
| Cisco | Ios Xe | 3.11s_3.11.1s |
| Cisco | Ios Xe | 3.11s_3.11.2s |
| Cisco | Ios Xe | 3.11s_3.11.3s |
| Cisco | Ios Xe | 3.11s_3.11.4s |
| Cisco | Ios Xe | 3.13s_3.13.0s |
| Cisco | Ios Xe | 3.13s_3.13.1s |
| Cisco | Ios Xe | 3.13s_3.13.4s |
| Cisco | Ios Xe | 3.14s_3.14.0s |
| Cisco | Ios Xe | 3.15s_3.15.1s |
| Cisco | Ios Xe | 3.15s_3.15.2s |
| Cisco | Webex Meeting Center | base |
| Cisco | Dx Series Ip Phones Firmware | 9.3\(2\) |
| Cisco | Ip Phone 7800 Series Firmware | 10.3\(1\) |
| Cisco | Ip Phone 8800 Series Firmware | 10.3\(2\) |
| Cisco | Ip Phone 8800 Series Firmware | 11.0\(1\) |
| Cisco | Unified Ip Phone 6900 Series Firmware | 9.3\(2\) |
| Cisco | Unified Ip Phone 7900 Series Firmware | 9.9\(9.99001.1\) |
| Cisco | Unified Ip Phone 7900 Series Firmware | 9.9_base |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.0\(1\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.0\(3\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.0\(4\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.1\(1\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.1\(2\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(1\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(2\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(2\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(3\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.2\(4\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(1\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(2\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(2\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.3\(4\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.4\(1\) |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.4\(1\)sr1 |
| Cisco | Unified Ip Phone 8900 Series Firmware | 9.4\(2\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(5\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(6\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(7\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(8\) |
| Cisco | Unified Wireless Ip Phone 7920 Firmware | 1.0\(9\) |
Showing 50 of 291 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6360?
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
How severe is CVE-2015-6360?
Severity scoring for CVE-2015-6360 is pending analysis. The EPSS model estimates a 8.28% probability of exploitation in the next 30 days.
How do I fix CVE-2015-6360?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2015-6360?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
