Denial of Service Vulnerability in Cisco Unified Communications Manager Products
CVE-2018-0409
Key Information:
- Vendor
- Cisco
- Status
- Vendor
- CVE Published:
- 15 August 2018
Summary
A vulnerability exists in the XCP Router service of Cisco Unified Communications Manager IM & Presence Service and related products, which could be exploited by an unauthenticated remote attacker to create a temporary service outage for all IM&P users. The issue stems from inadequate validation of user-supplied input. An attacker could send specially crafted IPv4 or IPv6 packets to the device's TCP port 7400, leading to a buffer over-read, causing the XCP Router service to crash and restart. This results in service disruption for users relying on the affected systems.
Affected Version(s)
TelePresence Video Communication Server (VCS) and Expressway = unspecified
Unified Communications Manager IM & Presence Service (CUCM IM&P) = unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved