CVE-2018-0139

Severity
8.6HIGH
EPSS
1.4%
top 19.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 13

Description

A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause the IVR connection to disconnect, creating a system-wide denial of service (DoS) condition. The vulnerability is due to improper handling of a TCP connection request when the IVR connection is already established. An attacker could exploit this vulnerability by initiating a crafted connection to the IP addre

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

CVEListV5cisco_unified_customer_voice_portalCisco Unified Customer Voice Portal

🔴Vulnerability Details

2
GHSA
GHSA-5g5r-5vxp-8rwg: A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an u2022-05-13
CVEList
CVE-2018-0139: A vulnerability in the Interactive Voice Response (IVR) management connection interface for Cisco Unified Customer Voice Portal (CVP) could allow an u2018-02-22

📋Vendor Advisories

1
Cisco
Cisco Unified Customer Voice Portal Interactive Voice Response Connection Denial of Service Vulnerability2018-02-22
CVE-2018-0139 (HIGH CVSS 8.6) | A vulnerability in the Interactive | cvebase.io