First published: Wed Jan 21 2004(Updated: )
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | =1.1 | |
Cisco Unified Contact Center Express Enhanced | =3.0 | |
Cisco IP Call Center Express Standard | =3.0 | |
Cisco IP Interactive Voice Response (IVR) | =3.0 | |
Cisco Personal Assistant | =1.3\(1\) | |
Cisco Personal Assistant | =1.3\(2\) | |
Cisco Personal Assistant | =1.3\(3\) | |
Cisco Personal Assistant | =1.3\(4\) | |
Cisco Personal Assistant | =1.4\(1\) | |
Cisco Personal Assistant | =1.4\(2\) | |
IBM Director Agent | =2.2 | |
IBM Director Agent | =3.11 | |
Cisco CallManager Express | =1.0 | |
Cisco CallManager Express | =2.0 | |
Cisco CallManager Express | =3.0 | |
Cisco CallManager Express | =3.1 | |
Cisco CallManager Express | =3.1\(2\) | |
Cisco CallManager Express | =3.1\(3a\) | |
Cisco CallManager Express | =3.2 | |
Cisco CallManager Express | =3.3 | |
Cisco CallManager Express | =3.3\(3\) | |
Cisco CallManager Express | =4.0 | |
Cisco Internet Service Node | ||
cisco conference connection | =1.1\(1\) | |
cisco conference connection | =1.2 | |
IBM mcs-7815-1000 | ||
IBM mcs-7815i-2.0 | ||
IBM mcs-7835i-2.4 | ||
IBM mcs-7835i | ||
IBM x330 | =8654 | |
IBM x330 | =8674 | |
IBM x340 | ||
IBM x342 | ||
IBM x345 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1759 is rated as a medium severity vulnerability due to its potential to cause denial of service by consuming CPU resources.
To mitigate CVE-2004-1759, it is recommended to apply any available patches or updates provided by Cisco for the affected products.
CVE-2004-1759 affects several Cisco products including Cisco Personal Assistant, Cisco Call Manager, and Cisco IP Interactive Voice Response.
Yes, CVE-2004-1759 can be exploited remotely by sending arbitrary packets to TCP port 14247 on the affected devices.
Most newer versions of the affected Cisco products have resolved the issues related to CVE-2004-1759, so updating is advisable.