CVE-2017-14114
RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recipient of RTP traffic, which allows remote attackers to obtain sensitive information or cause a denial of…
Does this matter?
Lower severity and a low EPSS score (1.24%). Track it; it rarely justifies an emergency change on its own.
Description
RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recipient of RTP traffic, which allows remote attackers to obtain sensitive information or cause a denial of service (communication outage) via crafted RTP packets.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 1.24% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- rtpproxy/rtpproxy
- Source
- cve@mitre.org
References
- https://rtpbleed.comPress/Media Coverage, Technical Description, Third Party Advisory
- https://rtpbleed.comPress/Media Coverage, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.