Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities
BID:16295
Info
Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities
| Bugtraq ID: | 16295 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2006 12:00AM |
| Updated: | Feb 07 2006 08:54PM |
| Credit: | This issue was reported to the vendor by a customer. |
| Vulnerable: |
Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES32 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES55 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES62 Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 4.0 Cisco Call Manager 3.3 (5)ES30 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 Cisco Call Manager |
| Not Vulnerable: |
Cisco Call Manager 4.1 (3)SR2 Cisco Call Manager 4.1 (3)SR1 Cisco Call Manager 4.1 (3)ES24 Cisco Call Manager 4.1 (3)ES07 Cisco Call Manager 4.1 (2)ES50 Cisco Call Manager 4.1 (2)ES33 Cisco Call Manager 4.0 (2a)SR2c Cisco Call Manager 4.0 (2a)SR2b Cisco Call Manager 4.0 (2a)ES56 Cisco Call Manager 4.0 (2a)ES40 Cisco Call Manager 3.3 (5)SR1a Cisco Call Manager 3.3 (5)ES24 Cisco Call Manager 3.3 (5) Cisco Call Manager 3.3 (4)ES25 Cisco Call Manager 3.3 (3)ES61 |
Discussion
Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities
CallManager is susceptible to multiple remote denial of service vulnerabilities.
These issues are documented in Cisco bugs CSCea53907, CSCsa86197, CSCsb16635 and CSCsb64161, which are available to Cisco customers.
Attackers may exploit these vulnerabilities to crash the affected service, effectively denying service to legitimate users.
CallManager is susceptible to multiple remote denial of service vulnerabilities.
These issues are documented in Cisco bugs CSCea53907, CSCsa86197, CSCsb16635 and CSCsb64161, which are available to Cisco customers.
Attackers may exploit these vulnerabilities to crash the affected service, effectively denying service to legitimate users.
Exploit / POC
Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities
Solution:
Cisco has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further details, and information on obtaining fixes.
Solution:
Cisco has released an advisory, along with fixes to address this issue. Please see the referenced advisory for further details, and information on obtaining fixes.
References
Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities
References:
References: