Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Customer Voice Portal Interactive Voice Response Connection Denial of Service Vulnerability

cisco-sa-20180221-cvp · High · Published · Updated

A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition. The vulnerability is due to improper handling of a TCP connection request when the IVR connection is already established. An attacker could exploit this vulnerability by initiating a crafted connection to the IP address of the targeted CVP device. An exploit could allow the attacker to disconnect the IVR to CVP connection, creating a DoS condition that prevents the CVP from accepting new, incoming calls while the IVR automatically attempts to re-establish the connection to the CVP. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180221-cvp

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2018-0139
Cisco Bug IDsCSCve70560
CVSS ScoreBase 8.6
Base 8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified Customer Voice Portal (CVP)

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2018-0139 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2018-0139 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2018-0139 Cisco OpenVuln
Cisco Unified Customer Voice Portal (CVP) CVE-2018-0139 Cisco OpenVuln