Cisco Video Surveillance IP Cameras Denial of Service Vulnerability
29 Mar. 2012
Summary
Successful exploitation of the vulnerability may result in DoS condition. Subsequent exploitation may result in sustained DoS condition, as the cameras will continue to reload.
.Vulnerable Systems:
*Cisco Video Surveillance IP Cameras 2421 series
*Cisco Video Surveillance IP Cameras 2500 series
*Cisco Video Surveillance IP Cameras 2600 series
.Immune Systems:
*Cisco Video Surveillance 2900 Series IP Cameras
*Cisco Video Surveillance 4000 Series IP Cameras
*Cisco Video Surveillance 5000 Series HD IP Dome Cameras
Cisco Video Surveillance 2421 and 2500 series cameras with software 1.1.x and 2.x before 2.4.0 and Video Surveillance 2600 series cameras with software before 4.2.0-13 allow remote attackers to cause a denial of service (device reload) by sending crafted RTSP packets over TCP, aka Bug IDs CSCtj96312, CSCtj39462, and CSCtl80175.
Vendor Status:
Cisco has issued an update to correct this vulnerability.