Cisco Bug: CSCus31503 - Oct 2014 OpenSSL Vulnerabilities
Jan 29, 2016
- Cisco Unified Attendant Consoles
Known Affected Releases
10.0 10.0(1) 10.5 10.5(2) 10.6(1)
Symptom: This product includes a version of OpenSSL that is affected by the vulnerability identified by the Common Vulnerability and Exposures (CVE) IDs: Following versions of Attendant Console includes 0.98 version of OpenSSL which is affected by the vulnerabilities identified by the Common Vulnerability and Exposures (CVE) IDs: CVE-2014-3513 - SRTP Memory Leak CVE-2014-3567 - Session Ticket Memory Leak Conditions: Authentication is needed in order to exploit these vulnerabilities. Product has implemented Open SSL to implement the https request to CUCM and requires authentication to connect to the server.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.
Bug Details Include
- Full Description (including symptoms, conditions and workarounds)
- Known Fixed Releases
- Related Community Discussions
- Number of Related Support Cases