CVE-2014-2175: Input Validation
Published May 2, 2014
·Updated
Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allow remote attackers to cause a denial of service (memory consumption) via crafted H.225 packets, aka Bug ID CSCtq78849.
Affected Software
26 affected components
Cisco TelePresence TC Software=4.0.0
Cisco TelePresence TC Software=4.0.1
Cisco TelePresence TC Software=4.0.4
Cisco TelePresence TC Software=4.1.1
Cisco TelePresence TC Software=4.1.2
Cisco TelePresence TC Software=4.2.0
Cisco TelePresence TC Software=4.2.1
Cisco TelePresence TC Software=4.2.2
Cisco TelePresence TC Software=4.2.3
Cisco TelePresence TC Software=4.2.4
Cisco TelePresence TC Software=5.0.0
Cisco TelePresence TC Software=5.0.1
Cisco TelePresence TC Software=5.0.2
Cisco TelePresence TC Software=5.1.0
Cisco TelePresence TC Software=5.1.1
Cisco TelePresence TC Software=5.1.2
Cisco TelePresence TC Software=5.1.3
Cisco TelePresence TC Software=5.1.4
Cisco TelePresence TC Software=5.1.5
Cisco TelePresence TC Software=5.1.6
Cisco TelePresence TC Software=5.1.7
Cisco Telepresence Te Software=4.1.0
Cisco Telepresence Te Software=4.1.1
Cisco Telepresence Te Software=4.1.2
Cisco Telepresence Te Software=4.1.3
Cisco Telepresence Te Software=6.0
Event History
May 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2175?
CVE-2014-2175 is classified as a denial of service vulnerability that can lead to memory consumption issues.
2
How do I fix CVE-2014-2175?
To mitigate CVE-2014-2175, update your Cisco TelePresence TC and TE software to a patched version.
3
Which versions are affected by CVE-2014-2175?
CVE-2014-2175 affects various versions of Cisco TelePresence TC Software 4.x, 5.x and TE Software 4.x, 6.0.
4
Can CVE-2014-2175 be exploited remotely?
Yes, CVE-2014-2175 can be exploited remotely through specially crafted H.225 packets.
5
What are the potential impacts of CVE-2014-2175?
Exploitation of CVE-2014-2175 can result in denial of service, causing the affected device to become unresponsive.