QID 317333
Date Published: 2023-07-17
QID 317333: Cisco Unified Communications Manager IM and Presence Service Denial of Service (DoS) Vulnerability (cisco-sa-cucm-imp-dos-49GL7rzT)
A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM and Presence Service (Unified CM IM and P) could allow an unauthenticated remote attacker to cause a temporary service outage for all Cisco Unified CM IM and P users who are attempting to authenticate to the service resulting in a denial of service (DoS) condition.
Affected Products:
Cisco Unified CM IM and P Release:
From 12.5(1) Prior to 12.5(1)SU7
From 14SU Prior to 14SU3
QID Detection Logic (Authenticated):
The check matches the Cisco Unified Communications Product version retrieved via Unix Auth using " Active Master Version:" command.
A successful exploit could allow the attacker to cause an unexpected restart of the authentication service, preventing new users from successfully authenticating.
Customers are advised to refer to cisco-sa-cucm-imp-dos-49GL7rzT for more information.
- cisco-sa-cucm-imp-dos-49GL7rzT -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-imp-dos-49GL7rzT
CVEs related to QID 317333
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-cucm-imp-dos-49GL7rzT |
|