Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6779


Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maximum size restriction. Therefore, the file is allowed to consume the majority of available disk space on the appliance. An attacker could exploit this vulnerability by sending crafted remote connection requests to the appliance. Successful exploitation could allow the attacker to increase the size of a system log file so that it consumes most of the disk space. The lack of available disk space could lead to a DoS condition in which the application functions could operate abnormally, making the appliance unstable. This vulnerability affects the following Cisco Voice Operating System (VOS)-based products: Emergency Responder, Finesse, Hosted Collaboration Mediation Fulfillment, MediaSense, Prime License Manager, SocialMiner, Unified Communications Manager (UCM), Unified Communications Manager IM and Presence Service (IM&P - earlier releases were known as Cisco Unified Presence), Unified Communication Manager Session Management Edition (SME), Unified Contact Center Express (UCCx), Unified Intelligence Center (UIC), Unity Connection, Virtualized Voice Browser. This vulnerability also affects Prime Collaboration Assurance and Prime Collaboration Provisioning. Cisco Bug IDs: CSCvd10872, CSCvf64322, CSCvf64332, CSCvi29538, CSCvi29543, CSCvi29544, CSCvi29546, CSCvi29556, CSCvi29571, CSCvi31738, CSCvi31741, CSCvi31762, CSCvi31807, CSCvi31818, CSCvi31823.


Published

2018-06-07T12:29:00.260

Last Modified

2024-11-21T03:30:30.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-399
  • Type: Primary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco emergency_responder < 10.5\(1a\) Yes
Application cisco emergency_responder < 11.5\(4\) Yes
Application cisco emergency_responder < 12.0su1 Yes
Application cisco emergency_responder 11.0\(1.10000.10\) Yes
Application cisco finesse < 11.5\(3\) Yes
Application cisco finesse 9.5\(1\) Yes
Application cisco hosted_collaboration_mediation_fulfillment < 11.5\(3\) Yes
Application cisco hosted_collaboration_mediation_fulfillment 9.5\(1\) Yes
Application cisco mediasense < 11.5su2 Yes
Application cisco mediasense 9.5\(1\) Yes
Application cisco prime_collaboration_assurance < 11.6_es16 Yes
Application cisco prime_collaboration_assurance < 12.1_es2 Yes
Application cisco prime_collaboration_provisioning 12.5 Yes
Application cisco prime_license_manager < 10.5.2 Yes
Application cisco prime_license_manager < 11.5\(1\)su5 Yes
Application cisco socialminer < 11.6.1 Yes
Application cisco unified_communications_manager < 10.5\(2\)su5 Yes
Application cisco unified_communications_manager < 11.0\(1a\)su4 Yes
Application cisco unified_communications_manager < 11.5\(1\)su3 Yes
Application cisco unified_communications_manager 10.5\(2.10000.5\) Yes
Application cisco unified_communications_manager 11.0\(1.10000.10\) Yes
Application cisco unified_communications_manager 11.5\(1.10000.6\) Yes
Application cisco unified_communications_manager 12.0 Yes
Application cisco unified_contact_center_express < 11.6\(1\) Yes
Application cisco unified_contact_center_express 9.0\(2\)su1.3 Yes
Operating System cisco unified_intelligence_center < 11.6\(1\) Yes
Operating System cisco unified_intelligence_center 9.5\(1\) Yes
Application cisco unity_connection < 10.5su5 Yes
Application cisco unity_connection < 11.5.1su3 Yes
Application cisco unity_connection 9.5\(0.9\)tt0 Yes
Application cisco unity_connection 12.0 Yes
Application cisco virtualized_voice_browser < 11.6\(1\) Yes

References