PT-2010-2338 · Cisco · Cisco Ios

Publicado

2010-03-24

·

Atualizado

2010-04-13

·

CVE-2010-0581

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS versions 12.3 through 12.4
Description The issue is related to an unspecified vulnerability in the SIP implementation, allowing remote attackers to execute arbitrary code via a malformed SIP message. Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software, which could allow an unauthenticated, remote attacker to cause a reload of an affected device when SIP operation is enabled. Remote code execution may also be possible.
Recommendations For devices running Cisco IOS versions 12.3 through 12.4, update to a version that addresses these vulnerabilities, as software updates have been released by Cisco. For devices that must run SIP, there are no workarounds, but mitigations are available to limit exposure of the vulnerabilities. As a temporary workaround, consider disabling SIP operation until a patch is available. Restrict access to SIP to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-0581

Produtos afetados

Cisco Ios