Cisco Expressway and TelePresence DOS Vulnerability
A vulnerability in the cluster database (CDB) management process used by several of Cisco’s remote-working and telepresence products could allow an authenticated attacker to remotely disrupt the CDB process.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A vulnerability in the cluster database (CDB) management process used by several of Cisco’s remote-working and telepresence products could allow an authenticated attacker to remotely disrupt the CDB process.
Affected platforms
The following platforms are known to be affected:
Threat details
This could result in a temporary denial-of-service (DoS). An attacker may exploit this vulnerability by sending specially-crafted URLs to the representational state transfer (REST) API of the software on an affected system. This causes the system to restart unexpectedly.
Remediation steps
Last edited: 17 February 2020 11:28 am