PT-2005-1273 · Cisco · Cisco Ios
Published
2005-01-19
·
Updated
2017-10-11
·
CVE-2005-0186
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.1YD, 12.2T, 12.3 and 12.3T
Description
The issue allows remote attackers to cause a denial of service, resulting in a device reboot, via a malformed packet to the SCCP port. This can be exploited repeatedly to produce a denial of service. The vulnerability is related to the processing of certain malformed control protocol messages when configured for the IOS Telephony Service, CallManager Express, or Survivable Remote Site Telephony.
Recommendations
For Cisco IOS versions 12.1YD, 12.2T, 12.3 and 12.3T, apply the free software upgrades made available by Cisco to address this issue.
As a temporary workaround, consider implementing workarounds available to mitigate the effects of the vulnerability.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios