SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-14114

RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recipient of RTP traffic, which allows remote attackers to obtain sensitive information or cause a denial of…

MEDIUM 6.5EPSS 1.24%

Does this matter?

Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.

Description

RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recipient of RTP traffic, which allows remote attackers to obtain sensitive information or cause a denial of service (communication outage) via crafted RTP packets.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
EPSS
1.24% probability · 68th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
rtpproxy/rtpproxy
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.