First published: Sun Oct 19 2014(Updated: )
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Video Communication Server Firmware | <=x8.1 | |
Cisco Expressway | <=x8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3370 has a high severity rating due to its potential to cause a denial of service by device reload through crafted SIP packets.
To address CVE-2014-3370, update Cisco TelePresence Video Communication Server or Expressway Software to a version later than X8.1.1.
CVE-2014-3370 affects Cisco TelePresence Video Communication Server and Cisco Expressway Software versions prior to X8.1.1.
The primary impact of CVE-2014-3370 is a denial of service, leading to impacted users being unable to access the services.
Organizations using affected versions of Cisco TelePresence or Expressway Software may be vulnerable to CVE-2014-3370.