Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco Unified Communications Manager IM & Presence Service Denial of Service Vulnerability

cisco-sa-20180815-ucmimps-dos · High · Published · Updated

A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an unauthenticated, remote attacker to cause a temporary service outage for all IM&P users, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious IPv4 or IPv6 packet to an affected device on TCP port 7400. An exploit could allow the attacker to overread a buffer, resulting in a crash and restart of the XCP Router service. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180815-ucmimps-dos

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2018-0409
Cisco Bug IDsCSCvg97663, CSCvi55947
CVSS ScoreBase 7.5
Base 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Unified Communications Manager IM and Presence Service, Cisco TelePresence Video Communication Server (VCS) Expressway

Related Products

Product CVE Evidence
Cisco Unified Communications Manager IM and Presence Service CVE-2018-0409 Cisco OpenVuln
Cisco Unified Communications Manager CVE-2018-0409 Cisco OpenVuln
Cisco TelePresence Video Communication Server (VCS) Expressway CVE-2018-0409 Cisco OpenVuln
Cisco TelePresence Video Communication Server (VCS) CVE-2018-0409 Cisco OpenVuln
Cisco TelePresence CVE-2018-0409 Cisco OpenVuln