This application requires Javascript for optimal performance.

Cisco.CallManager.Express.Malformed.Skinny.DoS

Release Date

Mar 29, 2011

Severity

medium

Impact

System Comromise: Remote attackers can crash the vulnerable systems.

Description

This indicates an attack attempt to exploit a denial-of-service vulnerability in Cisco 2800 Integrated Services Router.

This issue is caused by an error in the vulnerable software when handling malformed Cisco Skinny Client Control Protocol packets destined for the device. It may allow remote attackers to crash the vulnerable system by sending a crafted Skinny Client packet.

Affected Products

Cisco 2800 Integrated Services Router: 12.4(15)T10

Recommended Actions

Currently we are not aware of any patches supplied by the vendor for this issue.

Coverage

IPS
VCM

Reference/s

https://strikecenter.bpointsys.com/bps/advisory/BPS-2010-0003

Reference: VID-24820