PT-2018-1536 · Cisco · Cisco Unified Communications Manager Im/Presence Service+1
Published
2018-08-15
·
Updated
2020-08-31
·
CVE-2018-0409
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Communications Manager IM and Presence Service versions (affected versions not specified)
Cisco TelePresence Video Communication Server versions (affected versions not specified)
Description
The issue is caused by insufficient input validation in the XCP Router service, allowing a remote attacker to cause a denial of service condition by sending specially crafted IPv4 or IPv6 packets to TCP port 7400. This could result in a temporary service outage for all IM&P users. An exploit could allow the attacker to overread a buffer, resulting in a crash and restart of the XCP Router service.
Recommendations
For Cisco Unified Communications Manager IM and Presence Service, update to a version that fixes the issue.
For Cisco TelePresence Video Communication Server, update to a version that fixes the issue.
As a temporary workaround, consider restricting access to TCP port 7400 to minimize the risk of exploitation.
Fix
DoS
RCE
Out of bounds Read
Buffer Over-read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Telepresence Video Communication Server
Cisco Unified Communications Manager Im/Presence Service