Title: Cisco Voice Product IBM Director Agent Port Scan Denial Of Service Vulnerability
Severity: HIGH
Description:
IBM Director installed with Cisco voice products on IBM servers has been reported prone to a remote denial of service vulnerability. The issue is reported to present itself when port 14247, which is associated with the affected software, is scanned with a port scanner. This will cause the executable "twgipc.exe" to exponentially consume CPU resources until the server becomes unresponsive.
A remote attacker may exploit this vulnerability to render a target Cisco voice server inoperative until the affected server is rebooted. This denial of service may additionally have a system wide impact.
Affected Products:
- Cisco Call Manager 1.0.0
- Cisco Call Manager 2.0.0
- Cisco Call Manager 3.0.0
- Cisco Call Manager 3.1.0
- Cisco Call Manager 3.1.0 (2)
- Cisco Call Manager 3.1.0 (3a)
- Cisco Call Manager 3.2.0
- Cisco Call Manager 3.3.0
- Cisco Call Manager 3.3.0 (3)
- Cisco Call Manager 4.0.0
- Cisco Conference Connection 1.1.0 (1)
- Cisco Conference Connection 1.2.0
- Cisco Emergency Responder 1.1.0
- Cisco IP Call Center Express (IPCC Express) Enhanced 3.0.0
- Cisco IP Call Center Express (IPCC Express) Standard 3.0.0
- Cisco IP Interactive Voice Response (IP IVR) 3.0.0
- Cisco Internet Service Node
- Cisco Personal Assistant 1.3.0 (1)
- Cisco Personal Assistant 1.3.0 (2)
- Cisco Personal Assistant 1.3.0 (3)
- Cisco Personal Assistant 1.3.0 (4)
- Cisco Personal Assistant 1.4.0 (1)
- Cisco Personal Assistant 1.4.0 (2)
- Cisco VoIP Phone 7902G
- Cisco VoIP Phone 7905G
- Cisco VoIP Phone 7912G
- IBM Director Agent 2.2.0
- IBM Director Agent 3.1.0
- IBM Director Agent 3.11.0
- IBM MCS-7815-1000
- IBM MCS-7815I-2.0
- IBM MCS-7835I-2.4
- IBM MCS-7835I-3.0
- IBM X330 8654
- IBM X330 8674
- IBM X340
- IBM X342
- IBM X345
References:
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.