CVE-2014-2166: Input Validation
The SIP implementation in Cisco TelePresence TC Software 4.x and TE Software 4.x allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCto70562.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2166?
CVE-2014-2166 is classified as a denial of service vulnerability.
How do I fix CVE-2014-2166?
To fix CVE-2014-2166, upgrade to a more recent version of Cisco TelePresence TC or TE Software as recommended in Cisco's security advisory.
Which versions are affected by CVE-2014-2166?
CVE-2014-2166 affects Cisco TelePresence TC Software versions 4.0.0 to 4.2.4 and Cisco TelePresence TE Software versions 4.1.0 to 4.1.3.
Who is affected by CVE-2014-2166?
Organizations using vulnerable versions of Cisco TelePresence TC and TE Software are at risk from CVE-2014-2166.
What could attackers achieve with CVE-2014-2166?
Attackers could exploit CVE-2014-2166 to send crafted SIP packets that result in a denial of service, causing device reloads.