CVE-2014-2167: Input Validation
The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCua86589.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2167?
CVE-2014-2167 is classified as a denial of service vulnerability, allowing remote attackers to trigger device reloads.
How do I fix CVE-2014-2167?
To fix CVE-2014-2167, upgrade to the latest version of Cisco TelePresence TC Software or TE Software as specified in the vendor's advisory.
Which Cisco TelePresence versions are affected by CVE-2014-2167?
CVE-2014-2167 affects Cisco TelePresence TC Software versions 4.x and 5.x, and TE Software versions 4.x and 6.0.
What attack vector does CVE-2014-2167 utilize?
CVE-2014-2167 can be exploited using crafted SIP packets sent to vulnerable Cisco devices.
Is there a workaround for CVE-2014-2167?
There are no known workarounds for CVE-2014-2167, so it is recommended to apply the available patches or upgrades.