Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco TelePresence Video Communication Server SDP Over SIP Denial of Service Vulnerability

Cisco-SA-20150609-CVE-2015-0772 · Medium · Published · Updated

A vulnerability in the Session Description Protocol (SDP) parser of the Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause the Cisco VCS device to become unreachable due to a denial of service (DoS) attack caused by high CPU utilization. The vulnerability is due to a parsing error in the SDP parameter negotiation request. An attacker could exploit this vulnerability by initiating an SDP session over a Session Initiation Protocol (SIP) connection to the Cisco VCS device and sending a crafted SDP parameter negotiation request. A successful exploit could allow the attacker to take the VCS device offline due to high CPU utilization, resulting in a DoS condition. Cisco has confirmed the vulnerability; however, software updates are not available. To exploit this vulnerability, an attacker would need to send a crafted SDP parameter negotiation request to the targeted device. Depending on where the targeted system resides in an environment, an attacker may need to bypass firewall restrictions or other protection measures, which may reduce the likelihood of a successful exploit.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only trusted users to have network access.

Administrators can help protect affected systems from external attacks by using a solid firewall strategy.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2015-0772
Cisco Bug IDsCSCut42422
CVSS ScoreBase 5.4
Base 5.4 AV:N/AC:H/Au:N/C:N/I:N/A:C/E:H/RL:U/RC:C
Product Names From Source
Cisco TelePresence Video Communication Server (VCS)

Related Products

Product CVE Evidence
Cisco TelePresence Video Communication Server (VCS) CVE-2015-0772 Cisco OpenVuln
Cisco TelePresence CVE-2015-0772 Cisco OpenVuln