Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Communications Domain Manager Platform High CPU Utilization Denial of Service Vulnerability

Cisco-SA-20150123-CVE-2014-8020 · Medium · Published · Updated

A vulnerability in Cisco Unified Communications Domain Manager Platform Software could allow an unauthenticated, remote attacker to cause high CPU utilization, which may affect the performance of the system and make some services unavailable. The vulnerability is due to insufficient implementation of flooding attack controls. An attacker could exploit this vulnerability by sending malformed TCP and UDP packets at a high rate. Cisco has confirmed the vulnerability, but updated software is not available. To exploit the vulnerability, the attacker may need access to trusted or internal networks to transmit crafted data packets to the targeted system. This access requirement could limit the likelihood of a successful exploit.

Workarounds

Administrators are advised to contact the vendor regarding the availability of future updates.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-8020
Cisco Bug IDsCSCup25276
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:U/RC:C
Product Names From Source
Cisco Unified Communications Domain Manager Platform

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Unified Communications Domain Manager Platform known_affected cisco_csaf CVE-2014-8020 1

Related Products

Product CVE Evidence
Cisco Unified Communications Domain Manager CVE-2014-8020 Cisco OpenVuln
Cisco Unified Communications Domain Manager Platform CVE-2014-8020 Cisco OpenVuln