PT-2010-2338 · Cisco · Cisco Ios
Publicado
2010-03-24
·
Atualizado
2010-04-13
·
CVE-2010-0581
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.3 through 12.4
Description
The issue is related to an unspecified vulnerability in the SIP implementation, allowing remote attackers to execute arbitrary code via a malformed SIP message. Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software, which could allow an unauthenticated, remote attacker to cause a reload of an affected device when SIP operation is enabled. Remote code execution may also be possible.
Recommendations
For devices running Cisco IOS versions 12.3 through 12.4, update to a version that addresses these vulnerabilities, as software updates have been released by Cisco. For devices that must run SIP, there are no workarounds, but mitigations are available to limit exposure of the vulnerabilities. As a temporary workaround, consider disabling SIP operation until a patch is available. Restrict access to SIP to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Ios