CVE-2005-0186: Medium severity Cisco IOS vulnerability
Published Jan 19, 2005
·Updated
Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.
Affected Software
4 affected components
Cisco IOS=12.1yd
Cisco IOS=12.2t
Cisco IOS=12.3
Cisco IOS=12.3t
Event History
Jan 19, 2005
CVE Published
05:00 AM
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0186?
CVE-2005-0186 is classified as a denial of service vulnerability.
2
How do I fix CVE-2005-0186?
To fix CVE-2005-0186, update Cisco IOS to a version that is not affected by this vulnerability.
3
What systems are affected by CVE-2005-0186?
CVE-2005-0186 affects Cisco IOS versions 12.1YD, 12.2T, 12.3, and 12.3T when configured for specific telephony services.
4
What exploits are associated with CVE-2005-0186?
Exploitation of CVE-2005-0186 can be carried out via sending malformed packets to the SCCP port.
5
What is the impact of CVE-2005-0186?
The impact of CVE-2005-0186 is a potential remote device reboot, leading to service interruption.