Vulnerability in Cisco IOS Embedded Call Processing Solutions - Cisco Systems

This script is (C) 2010-2014 Tenable Network Security, Inc.


Synopsis :

The remote device is missing a vendor-supplied security patch.

Description :

Cisco Internetwork Operating System (IOS) Software release trains
12.1YD, 12.2T, 12.3 and 12.3T, when configured for the Cisco IOS
Telephony Service (ITS), Cisco CallManager Express (CME) or Survivable
Remote Site Telephony (SRST) may contain a vulnerability in processing
certain malformed control protocol messages.

See also :

http://www.nessus.org/u?e2861f8b
http://www.nessus.org/u?d064330c

Solution :

Apply the relevant patch referenced in Cisco Security Advisory
cisco-sa-20050119-itscme.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 4.0
(CVSS2#E:U/RL:W/RC:C)
Public Exploit Available : false

Family: CISCO

Nessus Plugin ID: 48979 (cisco-sa-20050119-itscmehttp.nasl)

Bugtraq ID: 12307

CVE ID: CVE-2005-0186