First published: Wed Jan 22 2014(Updated: )
The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Video Communication Server Firmware | <=x7.2.2 | |
Cisco TelePresence Video Communication Server Firmware | =x6.0 | |
Cisco TelePresence Video Communication Server Firmware | =x6.1 | |
Cisco TelePresence Video Communication Server Firmware | =x7.1 | |
Cisco TelePresence Video Communication Server Firmware | =x7.2 | |
Cisco TelePresence Video Communication Server Firmware | =x7.2.1 | |
Cisco TelePresence Video Communication Server Firmware | =x7.0 | |
Cisco TelePresence Video Communication Server Firmware | =x7.0.1 | |
Cisco TelePresence Video Communication Server Firmware | =x7.0.2 | |
Cisco TelePresence Video Communication Server Firmware | =x7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-0662 is classified as high due to its potential to cause a denial of service.
To fix CVE-2014-0662, upgrade the Cisco TelePresence VCS software to version 8.1 or later.
CVE-2014-0662 is caused by a crafted SDP message that leads to process failure in the SIP module.
Versions x7.0 to x7.2.2 and x6.0 to x6.1 are affected by CVE-2014-0662.
Yes, CVE-2014-0662 can be exploited remotely by sending a specially crafted SDP message.