CVE-2018-0358CWE-769

A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote…

published June 21, 2018

CVSS
EPSS
2%
Percentile
82.7
In the wild
Unconfirmed
What it is

A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to exhaustion of file descriptors while processing a high volume of traffic. An attacker could exploit this vulnerability by establishing a high number of concurrent TCP connections to the vulnerable system. An exploit could allow the attacker to cause a restart in a specific process, resulting in a temporary interruption of service. Cisco Bug IDs: CSCvh77056, CSCvh77058, CSCvh95264.

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
0.02367 · 82.7th percentile
Weakness
CWE-769 · DEPRECATED: Uncontrolled File Descriptor Consumption
Published
2018-06-21T11:00Z
EPSS history
Timeline
  • 21 JUN 11:00Z
    A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote…
    cvelistv5