Vulnerability CVE-2004-1759


Published: 2004-01-21   Modified: 2012-02-12

Description:
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.

Type:

CWE-399

(Resource Management Errors)

Vendor: IBM
Product: X330 
Version: 8674; 8654;
Product: Director agent 
Version: 3.11; 2.2;
Product: X340 
Product: Mcs-7815i-2.0 
Product: X345 
Product: Mcs-7835i-3.0 
Product: Mcs-7815-1000 
Product: X342 
Product: Mcs-7835i-2.4 
Vendor: Cisco
Product: Call manager 
Version:
4.0
3.3(3)
3.3
3.2
3.1(3a)
3.1(2)
3.1
3.0
2.0
1.0
Product: Ip call center express standard 
Version: 3.0;
Product: Ip call center express enhanced 
Version: 3.0;
Product: Ip interactive voice response 
Version: 3.0;
Product: Personal assistant 
Version:
1.4(2)
1.4(1)
1.3(4)
1.3(3)
1.3(2)
1.3(1)
Product: Conference connection 
Version: 1.2; 1.1(1);
Product: Emergency responder 
Version: 1.1;
Product: Internet service node 

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://www.kb.cert.org/vuls/id/721092
http://www.securityfocus.com/bid/9469
http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml
http://secunia.com/advisories/10696
http://xforce.iss.net/xforce/xfdb/14901
http://www.securitytracker.com/id?1008814
http://www.osvdb.org/3691
http://www.ciac.org/ciac/bulletins/o-066.shtml

Related CVE
CVE-2019-1780
A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevate...
CVE-2019-1860
A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center....
CVE-2019-1858
A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the SNMP application to leak system memory, which could c...
CVE-2019-1853
A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software...
CVE-2019-1851
A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE....
CVE-2019-1849
A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition...
CVE-2019-1846
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent atta...
CVE-2019-1833
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured policies. The vulnerability is due ...

Copyright 2019, cxsecurity.com

 

Back to Top