PT-2018-1536 · Cisco · Cisco Unified Communications Manager Im/Presence Service+1

Publicado

2018-08-15

·

Atualizado

2020-08-31

·

CVE-2018-0409

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager IM and Presence Service versions (affected versions not specified) Cisco TelePresence Video Communication Server versions (affected versions not specified)
Description The issue is caused by insufficient input validation in the XCP Router service, allowing a remote attacker to cause a denial of service condition by sending specially crafted IPv4 or IPv6 packets to TCP port 7400. This could result in a temporary service outage for all IM&P users. An exploit could allow the attacker to overread a buffer, resulting in a crash and restart of the XCP Router service.
Recommendations For Cisco Unified Communications Manager IM and Presence Service, update to a version that fixes the issue. For Cisco TelePresence Video Communication Server, update to a version that fixes the issue. As a temporary workaround, consider restricting access to TCP port 7400 to minimize the risk of exploitation.

Correção

DoS

RCE

Out of bounds Read

Buffer Over-read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01091
CVE-2018-0409

Produtos afetados

Cisco Telepresence Video Communication Server
Cisco Unified Communications Manager Im/Presence Service