SecurityTeam US
 
 Welcome to SecurityTeam US
 Monday, February 06 2012 @ 12:20 PM EST

Cisco IOS SCCP Control Protocol Message Denial of Service

   
Cisco SystemsSecureTest has reported a vulnerability in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error within the processing of control protocol messages and can be exploited to reload a vulnerable network device via a specially crafted control protocol message sent to the SCCP (Skinny Call Control Protocol) service.

The vulnerability affects the 12.1YD, 12.2T, 12.3, and 12.3T release trains configured for Cisco IOS Telephony Service (ITS), Cisco CallManager Express (CME), or Survivable Remote Site Telephony (SRST).

OPERATING SYSTEM:
Cisco IOS R12.x
Cisco IOS 12.x

SOLUTION:
See the patch matrix in the vendor advisory for information about fixes.
http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml#software

PROVIDED AND/OR DISCOVERED BY:
SecureTest

ORIGINAL ADVISORY:
Cisco:
http://www.cisco.com/warp/public/707/cisco-sa-20050119-itscme.shtml

VERIFY ADVISORY:
http://secunia.com/advisories/13913/

Secunia Security Advisories

 

What's Related

Story Options

Cisco IOS SCCP Control Protocol Message Denial of Service | 0 comments | Create New Account
The following comments are owned by whomever posted them. This site is not responsible for what they say.
 Copyright © 2012 SecurityTeam US
 All trademarks and copyrights on this page are owned by their respective owners.
  Get Firefox!
Dedicated Servers
Created this page in 0.32 seconds