CVE-2004-2629
Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 2.28% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- first virtual communications/click to meet express · first virtual communications/click to meet premier · first virtual communications/conference server · first virtual communications/v-gate
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/11192Vendor Advisory
- http://support.fvc.com/eng/docs/misc_docs/H.323_Security_Bulletin.pdf
- http://www.cert.org/advisories/CA-2004-01.htmlThird Party Advisory, US Government Resource
- http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
- http://secunia.com/advisories/11192Vendor Advisory
- http://support.fvc.com/eng/docs/misc_docs/H.323_Security_Bulletin.pdf
- http://www.cert.org/advisories/CA-2004-01.htmlThird Party Advisory, US Government Resource
- http://www.uniras.gov.uk/vuls/2004/006489/h323.htm
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.