CVE-2017-3792 is a critical vulnerability in a proprietary device driver within Cisco TelePresence MCU Software, affecting models like the 5300 Series, MSE 8510, and 4500 when running software version 4.3(1.68) or later in Passthrough content mode. This flaw, due to improper size validation during fragmented IPv4/IPv6 packet reassembly, allows an unauthenticated, remote attacker to overflow a buffer by sending crafted packets. With a CVSS score of 9.8 (Critical), it presents a low-complexity attack vector (AV:N/AC:L) that can lead to arbitrary code execution or a denial of service. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3_\(1.68\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_mcu_software:4.3_\(1.68\):*:*:*:*:*:*:* | ||
4.3_\(2.18\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_mcu_software:4.3_\(2.18\):*:*:*:*:*:*:* | ||
4.3_\(2.30\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_mcu_software:4.3_\(2.30\):*:*:*:*:*:*:* | ||
4.3_\(2.32\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_mcu_software:4.3_\(2.32\):*:*:*:*:*:*:* | ||
4.4_\(3.42\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_mcu_software:4.4_\(3.42\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.