Guest

Preview Tool

Cisco Bug: CSCux21905 - Cisco Unified Communications Manager Trust Verification Service Denial of Service Vulnerability

Last Modified

May 21, 2019

Products (1)

  • Cisco Unified Communications Manager (CallManager)

Known Affected Releases

10.0(1.10000.24) 10.5(2.10000.5) 11.0(1.10000.10) 9.1(2.10000.28)

Description (partial)

Symptom:
A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

The vulnerability is due to improper handling of Transport Layer Security (TLS) traffic by the affected software. An attacker could exploit this vulnerability by generating incomplete traffic streams. A successful exploit could allow the attacker to deny access to the TVS for an affected device, resulting in a DoS condition, until an administrator restarts the service.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170906-ucm

Conditions:
Device configured with default configuration.

Related Community Discussions

Corporate Directory - host not found intermitently
We have a new installation of a CUCM cluster (10.5.2.10000-5). The phones are a 7821 and 8851. Corporate directory was working fine but all of a sudden it just says Requesting... and then it says Host Not Found. Then all of a sudden it will start working on some phones but on others it will still not work. If we restart a phone on which it is working at the moment after reboot it doesn't work.   Does anyone have an idea how to fix this? Regards.  
Latest activity: Feb 11, 2016
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.