CVE-2011-3288: High severity cisco unified presence server vulnerability
Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and process crash) via a crafted XML document containing a large number of nested entity references, aka Bug IDs CSCtq89842 and CSCtq88547, a similar issue to CVE-2003-1564.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3288?
CVE-2011-3288 is classified as a denial of service vulnerability that can lead to memory and CPU exhaustion.
How do I fix CVE-2011-3288?
To fix CVE-2011-3288, upgrade Cisco Unified Presence to version 8.5(4) or later.
What types of attacks exploit CVE-2011-3288?
CVE-2011-3288 can be exploited by remote attackers through crafted XML documents that have excessive nested entity references.
What software versions are affected by CVE-2011-3288?
CVE-2011-3288 affects multiple versions of Cisco Unified Presence, including versions before 8.5(4).
What are the consequences of not addressing CVE-2011-3288?
Failure to address CVE-2011-3288 may result in service outages due to system crashes from excessive resource consumption.