CVE-2018-0086
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE traffic received on the CVP during communications with the Cisco Virtualized Voice Browser (VVB). An attacker could exploit this vulnerability by sending malformed SIP INVITE traffic to the targeted appliance. An exploit could allow the attacker to impact the availability of services and data on the device, causing a DoS condition. This vulnerability affects Cisco Unified CVP running any software release prior to 11.6(1). Cisco Bug IDs: CSCve85840.
Una vulnerabilidad en el servidor de aplicaciones de Cisco Unified Customer Voice Portal (CVP) podría permitir que un atacante remoto sin autenticar provoque una denegación de servicio (DoS) en el dispositivo afectado. La vulnerabilidad se debe al tráfico SIP INVITE mal formado recibido en el CVP durante las comunicaciones con Cisco Virtualized Voice Browser (VVB). Un atacante podría explotar esta vulnerabilidad mediante el envío de un tráfico SIP INVITE mal formado a través del dispositivo objetivo. Su explotación podría permitir que el atacante provoque un impacto en la disponibilidad de los servicios y datos en el dispositivo, causando una condición de denegación de servicio (DoS). Esta vulnerabilidad afecta a Cisco Unified CVP que ejecuten cualquier distribución anterior a 11.6(1). Cisco Bug IDs: CSCve85840.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-01-18 CVE Published
- 2023-07-21 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102745 | Third Party Advisory | |
http://www.securitytracker.com/id/1040220 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180117-cvp | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | <= 11.5 Search vendor "Cisco" for product "Unified Customer Voice Portal" and version " <= 11.5" | - |
Affected
|