CVE-2019-15289 describes multiple denial-of-service vulnerabilities in the video service of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software, impacting various Cisco Webex Board models. These vulnerabilities, stemming from insufficient input validation, allow an unauthenticated, remote attacker to crash the video service. Rated 7.5 HIGH, the attack requires no user interaction and has a low attack complexity, leading to a complete loss of availability. While no public exploit code or active exploitation is reported, it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:cisco:roomos:-:*:*:*:*:*:*:* | ||
< 9.8.0CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_collaboration_endpoint:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.