Cisco Unified Presence Engine Denial of Service Vulnerability
BID:29220
Info
Cisco Unified Presence Engine Denial of Service Vulnerability
| Bugtraq ID: | 29220 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1740 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2008 12:00AM |
| Updated: | May 14 2008 11:25PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Cisco Unified Presence Server 6.0 Cisco Unified Presence Server 1.0 |
| Not Vulnerable: |
Cisco Unified Presence Server 6.0(1) |
Discussion
Cisco Unified Presence Engine Denial of Service Vulnerability
Cisco Unified Presence Engine is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected application to crash, denying service to legitimate users.
This issue is documented by Cisco Bug ID CSCsh20972.
Cisco Unified Presence Engine is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected application to crash, denying service to legitimate users.
This issue is documented by Cisco Bug ID CSCsh20972.
Exploit / POC
Cisco Unified Presence Engine Denial of Service Vulnerability
To exploit this issue, attackers can use readily available network utilities.
To exploit this issue, attackers can use readily available network utilities.
Solution / Fix
Cisco Unified Presence Engine Denial of Service Vulnerability
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
References
Cisco Unified Presence Engine Denial of Service Vulnerability
References:
References:
- Cisco Homepage (Cisco )
- Cisco Unified Presence Homepage (Cisco)
- Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilitie (Cisco Systems Product Security Incident Response Team
) - Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilitie (Cisco)