{"api_version":"1","generated_at":"2026-07-23T19:40:26+00:00","cve":"CVE-2016-6448","urls":{"html":"https://cve.report/CVE-2016-6448","api":"https://cve.report/api/cve/CVE-2016-6448.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-6448","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-6448"},"summary":{"title":"CVE-2016-6448","description":"A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.","state":"PUBLISHED","assigner":"cisco","published_at":"2016-11-03 21:59:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-119","unspecified"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securitytracker.com/id/1037181","name":"http://www.securitytracker.com/id/1037181","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Meeting Server Buffer Overflow in Processing SDP Packets Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94076","name":"http://www.securityfocus.com/bid/94076","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cisco Meeting Server CVE-2016-6448 Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1","name":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-6448","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6448","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"Cisco Meeting Server before 2.0.3 and Acano Server before 1.9.5","version":"affected Cisco Meeting Server before 2.0.3 and Acano Server before 1.9.5","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"1.8.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"1.8_base","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"1.9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"1.9.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"2.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"2.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"2.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cisco","cpe5":"meeting_server","cpe6":"2.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2016","cve_id":"6448","cve":"CVE-2016-6448","epss":"0.075880000","percentile":"0.918920000","score_date":"2026-05-10","updated_at":"2026-05-11 00:14:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T01:29:20.048Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1"},{"name":"1037181","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1037181"},{"name":"94076","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/94076"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Cisco Meeting Server before 2.0.3 and Acano Server before 1.9.5","vendor":"n/a","versions":[{"status":"affected","version":"Cisco Meeting Server before 2.0.3 and Acano Server before 1.9.5"}]}],"datePublic":"2016-11-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0."}],"problemTypes":[{"descriptions":[{"description":"unspecified","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T09:57:01.000Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1"},{"name":"1037181","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1037181"},{"name":"94076","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/94076"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@cisco.com","ID":"CVE-2016-6448","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Cisco Meeting Server before 2.0.3 and Acano Server before 1.9.5","version":{"version_data":[{"version_value":"Cisco Meeting Server before 2.0.3 and Acano Server before 1.9.5"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"unspecified"}]}]},"references":{"reference_data":[{"name":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1","refsource":"CONFIRM","url":"https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-cms1"},{"name":"1037181","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037181"},{"name":"94076","refsource":"BID","url":"http://www.securityfocus.com/bid/94076"}]}}}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2016-6448","datePublished":"2016-11-03T21:00:00.000Z","dateReserved":"2016-07-26T00:00:00.000Z","dateUpdated":"2024-08-06T01:29:20.048Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-11-03 21:59:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-119","unspecified"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:1.8.15:*:*:*:*:*:*:*","matchCriteriaId":"B8E4843E-E44A-42E8-B83D-AEFC7A8BCE13"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:1.8_base:*:*:*:*:*:*:*","matchCriteriaId":"0CD09398-8DBF-4467-9BE3-A9297AE247AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:1.9.0:*:*:*:*:*:*:*","matchCriteriaId":"1691992B-DD39-43CA-BD51-800EEE19F224"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:1.9.2:*:*:*:*:*:*:*","matchCriteriaId":"53619071-8A6A-4230-BDEF-B0E1461217C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:2.0.0:*:*:*:*:*:*:*","matchCriteriaId":"C48DC084-1DD2-4878-B1DB-1035CAE3B918"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"1CA9A904-9AB5-4757-ABD1-0F6F933799BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:2.0.3:*:*:*:*:*:*:*","matchCriteriaId":"8FA8A21E-97BA-4326-9F7B-FCBD480134EF"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:2.0.4:*:*:*:*:*:*:*","matchCriteriaId":"1E6FA3F5-752D-45AB-A8CB-6488F409D933"},{"vulnerable":true,"criteria":"cpe:2.3:a:cisco:meeting_server:2.0.5:*:*:*:*:*:*:*","matchCriteriaId":"4B80C9BA-07EC-4183-9AAD-3229913C9FD7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"6448","Ordinal":"1","Title":"CVE-2016-6448","CVE":"CVE-2016-6448","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"6448","Ordinal":"1","NoteData":"A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.","Type":"Description","Title":"CVE-2016-6448"},{"CveYear":"2016","CveId":"6448","Ordinal":"2","NoteData":"2016-11-03","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"6448","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}