Cisco CallManager RISDC Remote Denial Of Service Vulnerability
BID:14250
Info
Cisco CallManager RISDC Remote Denial Of Service Vulnerability
| Bugtraq ID: | 14250 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2005 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Cisco Call Manager 4.0 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 |
| Not Vulnerable: |
Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 |
Discussion
Cisco CallManager RISDC Remote Denial Of Service Vulnerability
The CallManager RISDC (Realtime Information Server Data Collection) service is susceptible to a remote denial of service vulnerability.
This issue is documented in Cisco bug CSCed37403, which is available to Cisco customers.
If attackers repeatedly create, and then drop TCP connections to the vulnerable service, excessive memory resources will be consumed, potentially leading to further connections being refused.
This issue was originally documented in BID 14227.
The CallManager RISDC (Realtime Information Server Data Collection) service is susceptible to a remote denial of service vulnerability.
This issue is documented in Cisco bug CSCed37403, which is available to Cisco customers.
If attackers repeatedly create, and then drop TCP connections to the vulnerable service, excessive memory resources will be consumed, potentially leading to further connections being refused.
This issue was originally documented in BID 14227.
Exploit / POC
Cisco CallManager RISDC Remote Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Cisco CallManager RISDC Remote Denial Of Service Vulnerability
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
References
Cisco CallManager RISDC Remote Denial Of Service Vulnerability
References:
References: