Vulnerabilities > Cisco > Expressway

DATE CVE VULNERABILITY TITLE RISK
2018-08-06 CVE-2018-5390 Resource Exhaustion vulnerability in multiple products
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
7.5
2017-10-19 CVE-2017-12287 Improper Input Validation vulnerability in Cisco products
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial of service (DoS) condition.
network
low complexity
cisco CWE-20
4.3
2017-02-01 CVE-2017-3790 Improper Input Validation vulnerability in Cisco products
A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2016-12-14 CVE-2016-9207 7PK - Security Features vulnerability in Cisco Expressway X8.7.2/X8.8.3
A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts.
network
low complexity
cisco CWE-254
6.5