PT-2019-2132 · Cisco · Cisco Unified Communications Manager

Publicado

2019-04-17

·

Atualizado

2019-10-09

·

CVE-2019-1837

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager versions 10.5, 11.5, 12.0, 12.5
Description A vulnerability in the User Data Services (UDS) API could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the management GUI. The issue is due to improper validation of input parameters in the UDS API requests. An attacker could exploit this by sending a crafted request to the UDS API, potentially causing the Cisco DB service to quit unexpectedly and preventing admin access to the Unified CM management GUI. Manual intervention may be required to restore normal operation.
Recommendations For versions 10.5, 11.5, 12.0, 12.5, consider temporarily disabling the UDS API until a patch is available to prevent exploitation. Restrict access to the management GUI to minimize the risk of denial of service attacks. Avoid using the affected UDS API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Validation of Array Index

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01893
CVE-2019-1837

Produtos afetados

Cisco Unified Communications Manager