CVE-2014-3337: Input Validation
Published Aug 12, 2014
·Updated
The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428.
Affected Software
1 affected component
Cisco Unified Communications Domain Manager<=8.6\(.2\)
Event History
Aug 12, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3337?
CVE-2014-3337 has been classified with a severity score that indicates it can lead to a denial of service.
2
How do I fix CVE-2014-3337?
To mitigate CVE-2014-3337, upgrade to a version of Cisco Unified Communications Manager later than 8.6.2.
3
Who is affected by CVE-2014-3337?
CVE-2014-3337 affects users of Cisco Unified Communications Manager version 8.6.2 and earlier.
4
What type of attack does CVE-2014-3337 involve?
CVE-2014-3337 involves a crafted SIP message that causes a process crash.
5
Is authentication required to exploit CVE-2014-3337?
Yes, the vulnerability can be exploited by remote authenticated users.