CVE-2019-15289
Last modified
CVE-2019-15289 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to insufficient input validation. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
Multiple vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted traffic to the video service of an affected endpoint. A successful exploit could allow the attacker to cause the video service to crash, resulting in a DoS condition on an affected device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Roomos | All versions |
| Cisco | Telepresence Collaboration Endpoint | < 9.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15289?
How severe is CVE-2019-15289?
How do I fix CVE-2019-15289?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-15283Multiple vulnerabilities in Cisco Webex Network Recording Pl…7.8
- CVE-2019-15284Multiple vulnerabilities in Cisco Webex Network Recording Pl…7.8
- CVE-2019-15285Multiple vulnerabilities in Cisco Webex Network Recording Pl…7.8
- CVE-2019-15286Multiple vulnerabilities in Cisco Webex Network Recording Pl…7.8
- CVE-2019-15287Multiple vulnerabilities in Cisco Webex Network Recording Pl…7.8
- CVE-2019-15288A vulnerability in the CLI of Cisco TelePresence Collaborati…8.8
- CVE-2019-1529Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-15290Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-15291An issue was discovered in the Linux kernel through 5.2.9. T…
- CVE-2019-15292An issue was discovered in the Linux kernel before 5.0.9. Th…4.7
- CVE-2019-15293An issue was discovered in ACDSee Photo Studio Standard 22.1…
- CVE-2019-15294An issue was discovered in Gallagher Command Centre 8.10 bef…
Are you affected by CVE-2019-15289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
