Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway Series Denial of Service Vulnerability

cisco-sa-20190605-cucm-imp-dos · High · Published · Updated

A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote attacker to cause a service outage for users attempting to authenticate, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient controls for specific memory operations. An attacker could exploit this vulnerability by sending a malformed Extensible Messaging and Presence Protocol (XMPP) authentication request to an affected system. A successful exploit could allow the attacker to cause an unexpected restart of the authentication service, preventing users from successfully authenticating. Exploitation of this vulnerability does not impact users who were authenticated prior to an attack. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190605-cucm-imp-dos

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-1845
Cisco Bug IDsCSCvn00361, CSCvp51956
CVSS ScoreBase 8.6
Base 8.6 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco TelePresence Video Communication Server (VCS), Cisco Unified Communications Manager IM and Presence Service, Cisco Expressway, Cisco TelePresence Video Communication Server (VCS) Expressway

Related Products

Product CVE Evidence
Cisco Unified Communications Manager IM and Presence Service CVE-2019-1845 Cisco OpenVuln
Cisco Unified Communications Manager CVE-2019-1845 Cisco OpenVuln
Cisco TelePresence Video Communication Server (VCS) Expressway CVE-2019-1845 Cisco OpenVuln
Cisco TelePresence Video Communication Server (VCS) CVE-2019-1845 Cisco OpenVuln
Cisco TelePresence CVE-2019-1845 Cisco OpenVuln
Cisco Expressway CVE-2019-1845 Cisco OpenVuln