Skip to main content

Cisco Expressway and TelePresence DOS Vulnerability

A vulnerability in the cluster database (CDB) management process used by several of Cisco’s remote-working and telepresence products could allow an authenticated attacker to remotely disrupt the CDB process.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability in the cluster database (CDB) management process used by several of Cisco’s remote-working and telepresence products could allow an authenticated attacker to remotely disrupt the CDB process.

Threat details

This could result in a temporary denial-of-service (DoS). An attacker may exploit this vulnerability by sending specially-crafted URLs to the representational state transfer (REST) API of the software on an affected system. This causes the system to restart unexpectedly.

Remediation steps

Type Step

At the time of publication there are no fixes for this vulnerability.

Review Cisco Security Advisory (20171018-expressway-tp-vcs) for further information.


Last edited: 17 February 2020 11:28 am