PT-2018-13011 · Cisco · Cisco Unity Connection
Published
2018-10-05
·
Updated
2019-10-09
·
CVE-2018-15396
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Unity Connection (affected versions not specified)
Description
A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. This issue arises because the affected software does not restrict the maximum size of certain files that can be written to disk. An attacker with valid administrator credentials could exploit this by sending a crafted, remote connection request. A successful exploit could allow the attacker to write a file that consumes most of the available disk space, causing application functions to operate abnormally and leading to a DoS condition.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Unity Connection