SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9207

A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts.

MEDIUM 6.5EPSS 2.02%

Does this matter?

Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. Affected Products: This vulnerability affects Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS). More Information: CSCvc10834. Known Affected Releases: X8.7.2 X8.8.3. Known Fixed Releases: X8.9.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS
2.02% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-254
Affected
cisco/expressway
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.