CVE-2020-3160 MEDIUM

CVE-2020-3160: Cisco Meeting Server Extensible Messaging and Presence Protocol Denial of Service Vulnerability

Vendor Cisco
Product Cisco Meeting Server
Weakness CWE-20 · Input validation
Published February 19, 2020
Last update November 15, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition for users of XMPP conferencing applications. Other applications and processes are unaffected. The vulnerability is due to improper input validation of XMPP packets. An attacker could exploit this vulnerability by sending crafted XMPP packets to an affected device. An exploit could allow the attacker to cause process crashes and a DoS condition for XMPP conferencing applications.

Key dates

02Disclosure timeline

February 19, 2020 CVE published
November 15, 2024 Record updated