CVE-2014-2164: Input Validation
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCuj94651.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2164?
CVE-2014-2164 has a moderate severity rating due to its potential for causing denial of service through crafted SIP packets.
How do I fix CVE-2014-2164?
To fix CVE-2014-2164, you should upgrade your Cisco TelePresence TC or TE Software to the latest patched version provided by Cisco.
Which Cisco products are affected by CVE-2014-2164?
CVE-2014-2164 affects multiple versions of Cisco TelePresence TC Software and TE Software.
What type of attack does CVE-2014-2164 exploit?
CVE-2014-2164 is exploited by sending crafted SIP packets that cause the affected devices to reload.
Is there a workaround for CVE-2014-2164?
There are no documented workarounds for CVE-2014-2164; updating to a secure version is recommended.