First published: Fri May 02 2014(Updated: )
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.
Credit: ykramarz@cisco.com psirt@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence TE Software | =4.1.0 | |
Cisco TelePresence TE Software | =4.1.1 | |
Cisco TelePresence TE Software | =4.1.2 | |
Cisco TelePresence TE Software | =4.1.3 | |
Cisco TelePresence TE Software | =6.0 | |
Cisco TelePresence TE Software | =6.0.1 | |
Cisco TelePresence TC | =4.0.0 | |
Cisco TelePresence TC | =4.0.1 | |
Cisco TelePresence TC | =4.0.4 | |
Cisco TelePresence TC | =4.1.1 | |
Cisco TelePresence TC | =4.1.2 | |
Cisco TelePresence TC | =4.2.0 | |
Cisco TelePresence TC | =4.2.1 | |
Cisco TelePresence TC | =4.2.2 | |
Cisco TelePresence TC | =4.2.3 | |
Cisco TelePresence TC | =4.2.4 | |
Cisco TelePresence TC | =5.0.0 | |
Cisco TelePresence TC | =5.0.1 | |
Cisco TelePresence TC | =5.0.2 | |
Cisco TelePresence TC | =5.1.0 | |
Cisco TelePresence TC | =5.1.1 | |
Cisco TelePresence TC | =5.1.2 | |
Cisco TelePresence TC | =5.1.3 | |
Cisco TelePresence TC | =5.1.4 | |
Cisco TelePresence TC | =5.1.5 | |
Cisco TelePresence TC | =5.1.6 | |
Cisco TelePresence TC | =5.1.7 | |
Cisco TelePresence TC | =6.0.0 | |
=4.1.0 | ||
=4.1.1 | ||
=4.1.2 | ||
=4.1.3 | ||
=6.0 | ||
=6.0.1 | ||
=4.0.0 | ||
=4.0.1 | ||
=4.0.4 | ||
=4.1.1 | ||
=4.1.2 | ||
=4.2.0 | ||
=4.2.1 | ||
=4.2.2 | ||
=4.2.3 | ||
=4.2.4 | ||
=5.0.0 | ||
=5.0.1 | ||
=5.0.2 | ||
=5.1.0 | ||
=5.1.1 | ||
=5.1.2 | ||
=5.1.3 | ||
=5.1.4 | ||
=5.1.5 | ||
=5.1.6 | ||
=5.1.7 | ||
=6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2171 has a high severity rating due to its potential for remote code execution.
To fix CVE-2014-2171, update the affected Cisco TelePresence software to version 6.0.1 or later for TC Software and 6.0.2 or later for TE Software.
CVE-2014-2171 affects Cisco TelePresence TC Software versions 4.x through 6.x before 6.0.1 and TE Software versions 4.x and 6.0.x before 6.0.2.
Yes, CVE-2014-2171 can be exploited remotely through crafted SIP packets.
A heap-based buffer overflow in CVE-2014-2171 occurs when a program writes more data to a buffer on the heap than it can hold, potentially allowing an attacker to execute arbitrary code.