CVE-2014-2165: Input Validation
Published May 2, 2014
·Updated
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCtq72699.
Affected Software
26 affected components
Cisco Telepresence Te Software=4.1.0
Cisco Telepresence Te Software=4.1.1
Cisco Telepresence Te Software=4.1.2
Cisco Telepresence Te Software=4.1.3
Cisco Telepresence Te Software=6.0
Cisco TelePresence TC Software=4.0.0
Cisco TelePresence TC Software=4.0.1
Cisco TelePresence TC Software=4.0.4
Cisco TelePresence TC Software=4.1.1
Cisco TelePresence TC Software=4.1.2
Cisco TelePresence TC Software=4.2.0
Cisco TelePresence TC Software=4.2.1
Cisco TelePresence TC Software=4.2.2
Cisco TelePresence TC Software=4.2.3
Cisco TelePresence TC Software=4.2.4
Cisco TelePresence TC Software=5.0.0
Cisco TelePresence TC Software=5.0.1
Cisco TelePresence TC Software=5.0.2
Cisco TelePresence TC Software=5.1.0
Cisco TelePresence TC Software=5.1.1
Cisco TelePresence TC Software=5.1.2
Cisco TelePresence TC Software=5.1.3
Cisco TelePresence TC Software=5.1.4
Cisco TelePresence TC Software=5.1.5
Cisco TelePresence TC Software=5.1.6
Cisco TelePresence TC Software=5.1.7
Event History
May 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2165?
CVE-2014-2165 has a severity rating of High due to its potential to cause a denial of service.
2
How do I fix CVE-2014-2165?
To fix CVE-2014-2165, upgrade to a patched version of Cisco TelePresence TC Software or TE Software as specified in Cisco's advisory.
3
What are the affected versions for CVE-2014-2165?
CVE-2014-2165 affects Cisco TelePresence TC Software versions 4.x and 5.x, and TE Software versions 4.x and 6.0.
4
Can CVE-2014-2165 allow remote attacks?
Yes, CVE-2014-2165 allows remote attackers to exploit the vulnerability via crafted SIP packets.
5
What is the impact of CVE-2014-2165?
The impact of CVE-2014-2165 includes a potential device reload, leading to a denial of service.