CVE-2020-3160 describes a denial-of-service vulnerability in the Extensible Messaging and Presence Protocol (XMPP) feature of Cisco Meeting Server software, specifically impacting XMPP conferencing applications. This medium-severity vulnerability (CVSS 5.3) stems from improper input validation, allowing an unauthenticated, remote attacker to send crafted XMPP packets to cause process crashes and a DoS condition. While the attack complexity is low, only XMPP conferencing applications are affected, with other services remaining operational. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.0CPE matchmatch criteria | cpe:2.3:a:cisco:meeting_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.