First published: Thu Mar 01 2012(Updated: )
Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence System Software | <=x7.0 | |
Cisco TelePresence System Software | =x5.2 | |
Cisco TelePresence System Software | =x6.0 | |
Cisco TelePresence System Software | =x6.1 | |
Tandberg Video Communication Server | ||
Tandberg Video Communication Server | ||
Tandberg Video Communication Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0330 is classified as a high severity vulnerability due to the potential for remote attackers to cause a denial of service.
To address CVE-2012-0330, upgrade Cisco TelePresence Video Communication Server to a version above X7.0.1.
CVE-2012-0330 affects Cisco TelePresence System Software versions up to and including X7.0, as well as various models of the Cisco TelePresence Video Communication Server.
The attack in CVE-2012-0330 involves sending a malformed SIP message to the affected devices, leading to a device crash.
Yes, CVE-2012-0330 can be exploited remotely, allowing attackers to cause a denial of service without physical access to the device.