#VU14431 Improper input validation in Cisco Unified Communications Manager IM & Presence Service - CVE-2018-0409
Published: August 15, 2018 / Updated: August 16, 2018
Cisco Unified Communications Manager IM & Presence Service
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists in the XCP Router service due to improper validation of user-supplied input. A remote attacker can send a malicious IPv4 or IPv6 packet to an affected device on TCP port 7400, overread a buffer and cause the XCP Router service to crash and restart.