First published: Fri May 02 2014(Updated: )
Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45739.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence System Software | <=f9.3 | |
Cisco TelePresence System Software | =f9.0.1 | |
Cisco TelePresence System Software | =f9.0.2 | |
Cisco TelePresence System Software | =f9.1.0 | |
Cisco TelePresence System Software | =f9.1.1 | |
Cisco TelePresence System Software | =f9.1.2 | |
Cisco TelePresence System Software | =fnc9.1.0 | |
Cisco TelePresence System Software | =fnc9.1.1 | |
Cisco TelePresence System Software | =fnc9.1.2 | |
Cisco TelePresence System Software | =fnc9.3 | |
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco TelePresence MXP | ||
Cisco TelePresence MXP software | ||
Cisco TelePresence System codec 3000 MXP | ||
Cisco TelePresence System codec 6000 MXP | ||
Cisco TelePresence System 75 MXP | ||
Cisco TelePresence System Edge 85 MXP | ||
Cisco TelePresence System Edge 95 MXP | ||
All of | ||
Any of | ||
Cisco TelePresence System Software | <=f9.3 | |
Cisco TelePresence System Software | =f9.0.1 | |
Cisco TelePresence System Software | =f9.0.2 | |
Cisco TelePresence System Software | =f9.1.0 | |
Cisco TelePresence System Software | =f9.1.1 | |
Cisco TelePresence System Software | =f9.1.2 | |
Cisco TelePresence System Software | =fnc9.1.0 | |
Cisco TelePresence System Software | =fnc9.1.1 | |
Cisco TelePresence System Software | =fnc9.1.2 | |
Cisco TelePresence System Software | =fnc9.3 | |
Any of | ||
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco Tandberg Endpoint | ||
Cisco TelePresence MXP | ||
Cisco TelePresence MXP software | ||
Cisco TelePresence System codec 3000 MXP | ||
Cisco TelePresence System codec 6000 MXP | ||
Cisco TelePresence System 75 MXP | ||
Cisco TelePresence System Edge 85 MXP | ||
Cisco TelePresence System Edge 95 MXP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2156 is classified as a denial of service vulnerability that can cause the device to reload.
To mitigate CVE-2014-2156, upgrade the Cisco TelePresence System MXP Series Software to version F9.3.1 or later.
CVE-2014-2156 affects various versions of the Cisco TelePresence System MXP Series Software prior to F9.3.1.
The vulnerability allows remote attackers to exploit crafted SIP packets to trigger device reloads.
There are no documented workarounds for CVE-2014-2156; upgrading the software is the only solution.