Lucene search

K
ciscoCiscoCISCO-SA-20111107-CVE-2011-0941
HistoryNov 07, 2011 - 4:36 p.m.

Cisco IOS Software and Cisco Unified Communications Manager Session Initiation Protocol Packet Processing Memory Leak Vulnerability

2011-11-0716:36:55
tools.cisco.com
14

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.002

Percentile

55.5%

Cisco IOS Software and Cisco Unified Communications Manager contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

The vulnerability is due to improper processing of malformed packets by the affected software. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious network requests to the targeted system. If successful, the attacker could cause the device to become unresponsive, resulting in a DoS condition.

Cisco confirmed this vulnerability and released software updates.

To exploit the vulnerability, an attacker must send malicious SIP packets to affected systems. Most environments restrict external connections using SIP, likely requiring an attacker to have access to internal networks prior to an attack. In addition, in environments that separate voice and data networks, attackers may have no access to networks that service voice traffic and allow the transmission of SIP packets, further increasing the difficulty of an exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscoiosMatchany
OR
ciscounified_communications_managerMatchany
OR
ciscoiosMatchany
OR
ciscounified_communications_managerMatchany
VendorProductVersionCPE
ciscoiosanycpe:2.3:o:cisco:ios:any:*:*:*:*:*:*:*
ciscounified_communications_manageranycpe:2.3:a:cisco:unified_communications_manager:any:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.002

Percentile

55.5%

Related for CISCO-SA-20111107-CVE-2011-0941