QID 316973
Date Published: 2021-05-19
QID 316973: Cisco Unified Communications Manager IM and Presence Service Denial of Service Vulnerability (cisco-sa-imp-dos-uTx2dqu2)
A vulnerability in Cisco Unified Communications Manager IM and Presence Service (Unified CM IM and P) Software
could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service
on an affected device to restart, resulting in a denial of service (DoS) condition.
Affected Products
Cisco Unified CM IM and P Release 12.5(1)SU3
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.
A successful exploit could allow the attacker to cause a process to crash, resulting in a DoS condition for new login attempts.
Users who are authenticated at the time of the attack would not be affected.
Customers are advised to refer to cisco-sa-imp-dos-uTx2dqu2 for more information.
- cisco-sa-imp-dos-uTx2dqu2 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-imp-dos-uTx2dqu2
CVEs related to QID 316973
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-imp-dos-uTx2dqu2 |
|