CVE-2018-0086

Severity
8.6HIGH
EPSS
1.6%
top 18.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18
Latest updateMay 13

Description

A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE traffic received on the CVP during communications with the Cisco Virtualized Voice Browser (VVB). An attacker could exploit this vulnerability by sending malformed SIP INVITE traffic to the targeted appliance. An exploit could allow the attack

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

CVEListV5cisco_unified_customer_voice_portalCisco Unified Customer Voice Portal

🔴Vulnerability Details

2
GHSA
GHSA-7j8f-w9cg-569r: A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a2022-05-13
CVEList
CVE-2018-0086: A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a2018-01-18

📋Vendor Advisories

1
Cisco
Cisco Unified Customer Voice Portal Denial of Service Vulnerability2018-01-18