SB2017012506 - Remote denial of service in Cisco Expressway and TelePresence VCS
Published: January 25, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory corruption (CVE-ID: CVE-2017-3790)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to boundary error when processing h323 calls. A remote unauthenticated attacker can initiate connection to the vulnerable service, send specially crafted h224 data in Real-Time Transport Protocol (RTP) packets, trigger memory corruption and h323 call parser and crash the service.
Remediation
Install update from vendor's website.