CVE-2018-15396
Cisco Unity Connection File Upload Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software does not restrict the maximum size of certain files that can be written to disk. An attacker who has valid administrator credentials for an affected system could exploit this vulnerability by sending a crafted, remote connection request to an affected system. A successful exploit could allow the attacker to write a file that consumes most of the available disk space on the system, causing application functions to operate abnormally and leading to a DoS condition.
Una vulnerabilidad en el BAT (Bulk Administration Tool) en Cisco Unity Connection podría permitir que un atacante remoto autenticado provoque un gran uso del disco, lo que resulta en una condición de denegación de servicio (DoS). La vulnerabilidad existe debido a que el software afectado no restringe el tamaño máximo de ciertos archivos que pueden escribirse en el disco. Un atacante que cuente con credenciales válidas de administrador en un sistema afectado podría explotar esta vulnerabilidad enviando una petición de conexión remota manipulada a un sistema afectado. Su explotación con éxito podría permitir que el atacante escriba un archivo que consume la mayor parte del espacio de disco disponible en el sistema, provocando que las funciones de la aplicación operen de forma anormal y conduciendo a una denegación de servicio (DoS).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-17 CVE Reserved
- 2018-10-05 CVE Published
- 2024-08-12 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1041782 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unity Connection Search vendor "Cisco" for product "Unity Connection" | 12.5 Search vendor "Cisco" for product "Unity Connection" and version "12.5" | - |
Affected
|