Skip to main content

Cisco goes public with major vulns

posted onAugust 22, 2013
by l33tdawg

Users of Cisco's Unified Communications Manager, UCM instant messaging and presence, and Prime Central hosted collaboration system need to get busy with patches, after the Borg announced denial-of-service vulnerabilities across all three platforms.

UCM 7.1, Cisco advises, has an improper error handling vulnerability that can be used in denial-of-service. An attacker can hose the system by sending malformed registration messages.

There are also vulns in versions 8.5, 8.6 and 9.0 of UCM: some UDP ports don't rate-limit properly, and could therefore be hit with high-rate traffic for denial-of-service. The same versions also fail to rate-limit on UDP 5060, the SIP port.

Source

Tags

Cisco Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th