Cisco CallManager Multiple Failed Logins Remote Denial Of Service Vulnerability
BID:14253
Info
Cisco CallManager Multiple Failed Logins Remote Denial Of Service Vulnerability
| Bugtraq ID: | 14253 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2005 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
Cisco Call Manager 4.0 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 |
| Not Vulnerable: |
Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 |
Discussion
Cisco CallManager Multiple Failed Logins Remote Denial Of Service Vulnerability
CallManager is susceptible to a remote denial of service vulnerability when MLA (Multi Level Admin) is enabled.
This issue is documented in Cisco bug CSCef47060, which is available to Cisco customers.
Attackers may exploit this vulnerability by repeatedly attempting, and failing, to log into the affected service. It is reported that as much as 750 megabytes of memory may be consumed, resulting in a sever reduction in performance, possibly denying service to legitimate users.
This issue was originally documented in BID 14227.
CallManager is susceptible to a remote denial of service vulnerability when MLA (Multi Level Admin) is enabled.
This issue is documented in Cisco bug CSCef47060, which is available to Cisco customers.
Attackers may exploit this vulnerability by repeatedly attempting, and failing, to log into the affected service. It is reported that as much as 750 megabytes of memory may be consumed, resulting in a sever reduction in performance, possibly denying service to legitimate users.
This issue was originally documented in BID 14227.
Exploit / POC
Cisco CallManager Multiple Failed Logins Remote Denial Of Service Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Cisco CallManager Multiple Failed Logins Remote Denial Of Service Vulnerability
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
Solution:
Cisco has released an advisory, along with fixes to address this, and other issues. Please see the referenced advisory for further details, and information on obtaining fixes.
References
Cisco CallManager Multiple Failed Logins Remote Denial Of Service Vulnerability
References:
References: