CVE-2016-6445 is a critical vulnerability affecting the XMPP service in Cisco Meeting Server (before 2.0.6) and Acano Server (before 1.8.18 and 1.9.x before 1.9.6). This flaw, stemming from incorrect processing of a deprecated authentication scheme, allows an unauthenticated, remote attacker to masquerade as a legitimate user. With a CVSS score of 9.1 (CRITICAL), it presents a low-complexity attack vector with high impact on confidentiality and integrity, as an attacker could gain unauthorized system access. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.15CPE matchmatch criteria | cpe:2.3:a:cisco:meeting_server:1.8.15:*:*:*:*:*:*:* | ||
1.8_baseCPE matchmatch criteria | cpe:2.3:a:cisco:meeting_server:1.8_base:*:*:*:*:*:*:* | ||
1.9.0CPE matchmatch criteria | cpe:2.3:a:cisco:meeting_server:1.9.0:*:*:*:*:*:*:* | ||
1.9.2CPE matchmatch criteria | cpe:2.3:a:cisco:meeting_server:1.9.2:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:meeting_server:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.