#VU15218 Improper input validation in Cisco Unity Connection - CVE-2018-15396
Published: October 3, 2018 / Updated: October 9, 2018
Cisco Unity Connection
Cisco Systems, Inc
Description
The vulnerability allows a remote high-privileged attacker to cause DoS condition on the target system.
The vulnerability exists due to improper restriction of the maximum size of certain files that can be written to disk. A remote attacker who has valid administrator credentials for an affected system can send a specially crafted, remote connection request, write a file that consumes most of the available disk space on the system and cause application functions to operate abnormally and lead to a DoS condition.