CVE Feed

    Dashboard / CVE / CVE-2017-3792

    CVE-2017-3792

    A vulnerability in a proprietary device driver in the kernel of Cisco TelePresence Multipoint Control Unit (MCU) Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. The vulnerability is due to improper size validation when reassembling fragmented IPv4 or IPv6 packets. An attacker could exploit this vulnerability by sending crafted IPv4 or IPv6 fragments to a port receiving content in Passthrough content mode. An exploit could allow the attacker to overflow a buffer. If successful, the attacker could execute arbitrary code or cause a DoS condition on the affected system. Cisco TelePresence MCU platforms TelePresence MCU 5300 Series, TelePresence MCU MSE 8510 and TelePresence MCU 4500 are affected when running software version 4.3(1.68) or later configured for Passthrough content mode. Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available, but mitigations are available. Cisco Bug IDs: CSCuu67675.

    Published:Feb 1, 2017
    Last Modified:Apr 20, 2025
    EPS:Feb 1, 2017
    EPSS Score:0.01989
    CVSS Score:9.8

    Affected Products

    Vendor
    Cisco
    Product
    Telepresence Mcu 4505
    Vendor
    Cisco
    Product
    Telepresence Mcu 4510
    Vendor
    Cisco
    Product
    Telepresence Mcu 4515
    Vendor
    Cisco
    Product
    Telepresence Mcu 4520
    Vendor
    Cisco
    Product
    Telepresence Mcu 5310
    Vendor
    Cisco
    Product
    Telepresence Mcu 5320
    Vendor
    Cisco
    Product
    Telepresence Mcu Mse 8510
    Vendor
    Cisco
    Product
    Telepresence Mcu Software

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High