Denial of Service Vulnerability in Cisco Unified Communications Manager Products
CVE-2018-0409
7.5HIGH
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 15 August 2018
What is CVE-2018-0409?
A vulnerability exists in the XCP Router service of Cisco Unified Communications Manager IM & Presence Service and related products, which could be exploited by an unauthenticated remote attacker to create a temporary service outage for all IM&P users. The issue stems from inadequate validation of user-supplied input. An attacker could send specially crafted IPv4 or IPv6 packets to the device's TCP port 7400, leading to a buffer over-read, causing the XCP Router service to crash and restart. This results in service disruption for users relying on the affected systems.
Affected Version(s)
TelePresence Video Communication Server (VCS) and Expressway = unspecified
Unified Communications Manager IM & Presence Service (CUCM IM&P) = unspecified