Guest

Preview Tool

Cisco Bug: CSCus31503 - Oct 2014 OpenSSL Vulnerabilities

Last Modified

Jan 29, 2016

Products (1)

  • Cisco Unified Attendant Consoles

Known Affected Releases

10.0 10.0(1) 10.5 10.5(2) 10.6(1)

Description (partial)

Symptom:
This product includes a version of OpenSSL that is affected by the vulnerability identified by the Common Vulnerability and Exposures (CVE) IDs:

Following versions of Attendant Console includes 0.98 version of OpenSSL which is affected by the vulnerabilities identified by the Common Vulnerability and Exposures (CVE) IDs:

CVE-2014-3513 - SRTP Memory Leak 
CVE-2014-3567 - Session Ticket Memory Leak

Conditions:
Authentication is needed in order to exploit these vulnerabilities.

Product has implemented Open SSL to implement the https request to CUCM and requires authentication to connect to the server.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.