Vulnslist

find the latest Cisco vulnerabilities

Multiple Vulnerabilities in Cisco PGW Softswitch

cisco-sa-20100512-pgw · High · Published · Updated

Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages. Successful exploitation of all but one of these vulnerabilities can crash the affected device. Exploitation of the remaining vulnerability will not crash the affected device, but it can lead to a denial-of-service (DoS) condition in which no new TCP-based connections will be accepted or created. Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100512-pgw.

Workarounds

No workaround information imported yet.

CVEsCVE-2010-0601, CVE-2010-0602, CVE-2010-0603, CVE-2010-0604, CVE-2010-1561, CVE-2010-1562, CVE-2010-1563, CVE-2010-1565, CVE-2010-1567
Cisco Bug IDsNA
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C/CDP:N/TD:N/CR:ND/IR:ND/AR:ND
Product Names From Source
Cisco PGW 2200 Softswitch

Related Products

Product CVE Evidence
Cisco PGW 2200 Softswitch CVE-2010-0601 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-0602 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-0603 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-0604 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-1561 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-1562 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-1563 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-1565 Cisco OpenVuln
Cisco PGW 2200 Softswitch CVE-2010-1567 Cisco OpenVuln