Cisco TelePresence Video Communication Server Session Initiation Protocol Denial of Service Vulnerability
9 Mar. 2012
Summary
These vulnerabilities are triggered by a crafted Session Initiation Protocol (SIP) packet that is sent to an affected device on either TCP and UDP ports 5060 or 5061
Vulnerable Systems:
* Cisco TelePresence Video Communication Server version 7.0
* Cisco TelePresence Video Communication Server version 6.1
* Cisco TelePresence Video Communication Server version 6.0
* Cisco TelePresence Video Communication Server version 5.2
Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319..
Vendor Status:
Cisco has released free software updates that address this vulnerability.