QID 317051
Date Published: 2021-09-28
QID 317051: Cisco Internetwork Operating System (IOS) and IOS XE Software FXO Interface Destination Pattern Bypass Vulnerability (cisco-sa-fxo-pattern-bypass-jUXgygYv)
A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and
Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers.
Affected Products
Cisco devices if they are running a vulnerable release of Cisco IOS or IOS XE Software and both of the following are true:
There is a destination pattern with at least one wildcard configured for an FXO interface.
The device is enabled to support incoming calls via ISDN or SIP.
QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.
A successful exploit could allow the attacker to conduct toll fraud, resulting in unexpected financial impact to affected customers.
Customers are advised to refer to cisco-sa-fxo-pattern-bypass-jUXgygYv for more information.
- cisco-sa-fxo-pattern-bypass-jUXgygYv -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fxo-pattern-bypass-jUXgygYv
CVEs related to QID 317051
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-fxo-pattern-bypass-jUXgygYv |
|