PT-2018-1536 · Cisco · Cisco Unified Communications Manager Im/Presence Service+1
Publicado
2018-08-15
·
Atualizado
2020-08-31
·
CVE-2018-0409
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Communications Manager IM and Presence Service versions (affected versions not specified)
Cisco TelePresence Video Communication Server versions (affected versions not specified)
Description
The issue is caused by insufficient input validation in the XCP Router service, allowing a remote attacker to cause a denial of service condition by sending specially crafted IPv4 or IPv6 packets to TCP port 7400. This could result in a temporary service outage for all IM&P users. An exploit could allow the attacker to overread a buffer, resulting in a crash and restart of the XCP Router service.
Recommendations
For Cisco Unified Communications Manager IM and Presence Service, update to a version that fixes the issue.
For Cisco TelePresence Video Communication Server, update to a version that fixes the issue.
As a temporary workaround, consider restricting access to TCP port 7400 to minimize the risk of exploitation.
Correção
DoS
RCE
Out of bounds Read
Buffer Over-read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Telepresence Video Communication Server
Cisco Unified Communications Manager Im/Presence Service