CVE-2014-3369: Cisco Expressway Software

High severity, CVSS 7.1. EPSS: 2.4% chance of exploitation in the next 30 days.

The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.

Affected products

  • Cisco Expressway Software: up to and including x8.1
  • Cisco Telepresence Video Communication Server Software: up to and including x8.1

Published 2014-10-19. Last modified 2026-06-17.