Cisco Security Advisory en-us 1992-2010 Cisco Systems, Inc. All rights reserved. Security Advisories Cisco Systems, Inc. 15 Cisco TelePresence Supervisor MSE 8050 Denial of Service Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130515-mse?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco TelePresence Supervisor MSE 8050 Denial of Service Vulnerability&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco TelePresence Supervisor MSE 8050 Denial of Service Vulnerability" border='0' height='0' width='0'></img>Cisco TelePresence Supervisor MSE 8050 contains a vulnerability that may allow an unauthenticated, remote attacker to cause high CPU utilization and a reload of the affected system.<br /> <br /> Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.<br /> <br /> This advisory is available at the following link:<br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130515-mse">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130515-mse</a> Wed, 2013 May 15 09:00:00 PDT Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software" border='0' height='0' width='0'></img>Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "Details" section for more information on the vulnerabilities. These vulnerabilities can be exploited independently; however, more than one vulnerability could be exploited on the same device.<br /> <br /> Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available. This advisory is available at the following link:<br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp</a> Fri, 2013 May 10 12:30:21 PDT Cisco Prime Data Center Network Manager Remote Command Execution Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-dcnm?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco Prime Data Center Network Manager Remote Command Execution Vulnerability&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco Prime Data Center Network Manager Remote Command Execution Vulnerability" border='0' height='0' width='0'></img>Cisco Prime Data Center Network Manager (DCNM) contains a remote command execution vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands on the computer that is running the Cisco Prime DCNM application.<br /> <br /> Cisco has released free software updates that address this vulnerability.<br /> <br /> This advisory is available at the following link:<br /> <br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-dcnm">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-dcnm</a><br /> <br /> <strong>Note:</strong> After this advisory was initially published, it was found that in addition to the DCNM SAN server component that is part of the DCNM solution, the DCNM LAN server is also affected by the same vulnerability. This advisory has been updated to revision 2.0 to indicate that the DCNM LAN server component is also vulnerable, to provide the Cisco bug ID that tracks the vulnerability in the DCNM LAN server component, and to update fixed software information. Wed, 2013 May 08 09:00:40 PDT Multiple Vulnerabilities in Cisco Unified Computing System http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-ucsmulti?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Multiple Vulnerabilities in Cisco Unified Computing System&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Multiple Vulnerabilities in Cisco Unified Computing System" border='0' height='0' width='0'></img>Managed and standalone Cisco Unified Computing System (UCS) deployments contain one or more of the vulnerabilities: <ul> <li><strong>Cisco Unified Computing System LDAP User Authentication Bypass Vulnerability</strong></li> <li><strong>Cisco Unified Computing System IPMI Buffer Overflow Vulnerability</strong></li> <li><strong>Cisco Unified Computing Management API Denial of Service Vulnerability</strong></li> <li><strong>Cisco Unified Computing System Information Disclosure Vulnerability</strong></li> <li><strong>Cisco Unified Computing System KVM Authentication Bypass Vulnerability</strong></li> </ul> Cisco has released free software updates that address these vulnerabilities.&nbsp; These vulnerabilities affect only Cisco UCS.&nbsp; Additional vulnerabilities that affect the NX-OS base operating system of UCS are described in Multiple Vulnerabilities in Cisco NX-OS-Based Products.<br /> <br /> <br /> This advisory is available at the following link:<br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-ucsmulti">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-ucsmulti</a> Tue, 2013 April 30 07:19:29 PDT Multiple Vulnerabilities in Cisco NX-OS-Based Products http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-nxosmulti?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Multiple Vulnerabilities in Cisco NX-OS-Based Products&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Multiple Vulnerabilities in Cisco NX-OS-Based Products" border='0' height='0' width='0'></img>Cisco Nexus, Cisco Unified Computing System (UCS), Cisco MDS 9000 Series Multilayer Switches, and Cisco 1000 Series Connected Grid Routers (CGR) are all based on the Cisco NX-OS operating system.&nbsp; These products are affected by one or more of the following vulnerabilities: <ul> <li><strong>Multiple Cisco Discovery Protocol Vulnerabilities in Cisco NX-OS-Based Products</strong></li> <li><strong>Cisco NX-OS Software SNMP and License Manager Buffer Overflow Vulnerability</strong></li> <li><strong>Cisco NX-OS Software SNMP Buffer Overflow Vulnerability</strong></li> <li><strong>Cisco NX-OS Software Jumbo Packet Denial of Service Vulnerability</strong></li> </ul> <br /> Cisco has released free software updates that address these vulnerabilities. <br /> <br /> This advisory is available at the following link:<br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-nxosmulti" originalattribute="href" originalpath="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-nxosmulti">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-nxosmulti</a> Fri, 2013 April 26 12:40:02 PDT Cisco Device Manager Command Execution Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-fmdm?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco Device Manager Command Execution Vulnerability&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco Device Manager Command Execution Vulnerability" border='0' height='0' width='0'></img>Cisco Device Manager contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands on a client host with the privileges of the user. This vulnerability affects Cisco Device Manager for the Cisco MDS 9000 Family and Cisco Nexus 5000 Series Switches when it is installed or launched via the Java Network Launch Protocol (JNLP) on a host running Microsoft Windows. <br /> <br /> Cisco Device Manager installed or launched from Cisco Prime Data Center Network Manager (DCNM) or Cisco Fabric Manager is not affected. This vulnerability can only be exploited if the JNLP file is executed on systems running Microsoft Windows. The vulnerability affects the confidentiality, integrity, and availability of the client host performing the installation or execution of Cisco Device Manager via JNLP file. There is no impact on the Cisco MDS 9000 Family or Cisco Nexus 5000 Series Switches.<br /> <br /> Cisco has released free software updates that address this vulnerability in the Cisco Device Manager for Cisco MDS 9000 Family Switches. Cisco Nexus 5000 Series Switches have discontinued the support of the Cisco Device Manager installation via JNLP and updates are not available.<br /> <br /> Workarounds that mitigate this vulnerability are available. This advisory is available at the following link:<br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-fmdm">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130424-fmdm</a> Wed, 2013 April 24 09:00:00 PDT Multiple Vulnerabilities in Cisco IOS XE Software for 1000 Series Aggregation Services Routers http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-asr1000?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Multiple Vulnerabilities in Cisco IOS XE Software for 1000 Series Aggregation Services Routers&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Multiple Vulnerabilities in Cisco IOS XE Software for 1000 Series Aggregation Services Routers" border='0' height='0' width='0'></img>Cisco IOS XE Software for 1000 Series Aggregation Services Routers (ASR) contains the following denial of service (DoS) vulnerabilities:<br /> <br /> <ul> <li>Cisco IOS XE Software IPv6 Multicast Traffic Denial of Service Vulnerability</li> <li>Cisco IOS XE Software MVPNv6 Traffic Denial of Service Vulnerability</li> <li>Cisco IOS XE Software L2TP Traffic Denial of Service Vulnerability </li> <li>Cisco IOS XE Software Bridge Domain Interface Denial of Service Vulnerability</li> <li>Cisco IOS XE Software SIP Traffic Denial of Service Vulnerability </li> </ul> <br /> These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the others.<br /> <br /> Successful exploitation of any of these vulnerabilities could allow an unauthenticated remote attacker to trigger a reload of the Embedded Services Processors (ESP) card or the Route Processor (RP) card, causing an interruption of services.<br /> Repeated exploitation could&nbsp;result in a sustained DoS condition.<br /> <br /> <strong>Note:&nbsp;</strong>Cisco IOS Software and Cisco IOS-XR Software are not affected by these vulnerabilities.<br /> <br /> Cisco has released free software updates that address these vulnerabilities. <br /> <br /> This advisory is available at the following link:<br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-asr1000">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-asr1000</a><br /> Wed, 2013 April 17 12:11:35 PDT Cisco Network Admission Control Manager SQL Injection Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130417-nac?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco Network Admission Control Manager SQL Injection Vulnerability &vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco Network Admission Control Manager SQL Injection Vulnerability " border='0' height='0' width='0'></img>Cisco Network Admission Control (NAC) Manager contains a vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code and take full control of the vulnerable system.&nbsp;A successful attack could allow an unauthenticated attacker to access, create or modify any information in the NAC Manager database.&nbsp;<br /> <br /> Cisco has released free software updates that address this vulnerability.&nbsp;<br /> <br /> There are no workarounds for this vulnerability.<br /> <br /> This advisory is available at the following link:&nbsp;<a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130417-nac">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130417-nac</a> Wed, 2013 April 17 09:00:00 PDT Cisco TelePresence Infrastructure Denial of Service Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130417-tpi?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco TelePresence Infrastructure Denial of Service Vulnerability&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco TelePresence Infrastructure Denial of Service Vulnerability" border='0' height='0' width='0'></img>Cisco TelePresence multipoint control unit (MCU) and Cisco TelePresence Server contain a vulnerability that could allow an unauthenticated, remote attacker to trigger the reload of an affected system.<br /> <br /> Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link:<br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130417-tpi">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130417-tpi</a> Wed, 2013 April 17 09:00:00 PDT Cisco IOS Software IP Service Level Agreement Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-ipsla?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco IOS Software IP Service Level Agreement Vulnerability&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco IOS Software IP Service Level Agreement Vulnerability" border='0' height='0' width='0'></img><!--- IP SLA 010-summary 0.4 ---> <p>The Cisco IOS Software implementation of the IP Service Level Agreement (IP SLA) feature contains a vulnerability in the validation of IP SLA packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. </p> <p>Cisco has released free software updates that address this vulnerability. Mitigations for this vulnerability are available. </p> <p>This advisory is available at the following link: <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-ipsla">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-ipsla</a> </p> <p><p>Note: The March 27, 2013, Cisco IOS Software Security Advisory bundled publication includes seven Cisco Security Advisories.&nbsp;All advisories address vulnerabilities in Cisco IOS Software. Each Cisco IOS Software Security Advisory lists the Cisco IOS Software releases that correct the vulnerability or vulnerabilities detailed in the advisory as well as the Cisco IOS Software releases that correct all Cisco IOS Software vulnerabilities in the March 2013 bundled publication. </p> <p>Individual publication links are in "Cisco Event Response: Semiannual Cisco IOS Software Security Advisory Bundled Publication" at the following link: </p> <p><a href="http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar13.html">http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar13.html</a></p> </p> Fri, 2013 April 12 07:44:06 PDT Cisco IOS Software Network Address Translation Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-nat?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco IOS Software Network Address Translation Vulnerability&vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco IOS Software Network Address Translation Vulnerability" border='0' height='0' width='0'></img><!--- NAT 010-summary 0.6 ---> <p>The Cisco IOS Software implementation of the virtual routing and forwarding (VRF) aware network address translation (NAT) feature contains a vulnerability when translating IP packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. </p> <p>Cisco has released free software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. </p> <p>This advisory is available at the following link: </p> <p><a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-nat">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-nat</a> </p> <p><p>Note: The March 27, 2013, Cisco IOS Software Security Advisory bundled publication includes seven Cisco Security Advisories.&nbsp;All advisories address vulnerabilities in Cisco IOS Software. Each Cisco IOS Software Security Advisory lists the Cisco IOS Software releases that correct the vulnerability or vulnerabilities detailed in the advisory as well as the Cisco IOS Software releases that correct all Cisco IOS Software vulnerabilities in the March 2013 bundled publication. </p> <p>Individual publication links are in "Cisco Event Response: Semiannual Cisco IOS Software Security Advisory Bundled Publication" at the following link: </p> <p><a href="http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar13.html">http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar13.html</a></p> </p> Thu, 2013 April 11 10:17:58 PDT Cisco IOS Software Smart Install Denial of Service Vulnerability http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-smartinstall?vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_p=Cisco IOS Software Smart Install Denial of Service Vulnerability &vs_k=1 <a target="_blank" href=" "><b> </b> </a><br/><br/><img src="http://www.cisco.com/swa/j/zag2_vs_log1.asc?Log=1&vs_f=Cisco Security Advisory&vs_cat=Security Intelligence&vs_type=RSS&vs_k=1&vs_p=Cisco IOS Software Smart Install Denial of Service Vulnerability " border='0' height='0' width='0'></img>The Smart Install client feature in Cisco IOS Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.<br /> <br /> Affected devices that are configured as Smart Install clients are vulnerable.<br /> <br /> Cisco has released free software updates that address this vulnerability. There are no workarounds for devices that have the Smart Install client feature enabled.<br /> <br /> This advisory is available at the following link:<br /> <br /> <a href="http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-smartinstall">http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130327-smartinstall</a><br /> <br /> <p>Note: The March 27, 2013, Cisco IOS Software Security Advisory bundled publication includes seven Cisco Security Advisories.&nbsp;All advisories address vulnerabilities in Cisco IOS Software. Each Cisco IOS Software Security Advisory lists the Cisco IOS Software releases that correct the vulnerability or vulnerabilities detailed in the advisory as well as the Cisco IOS Software releases that correct all Cisco IOS Software vulnerabilities in the March 2013 bundled publication. </p> <p>Individual publication links are in "Cisco Event Response: Semiannual Cisco IOS Software Security Advisory Bundled Publication" at the following link: </p> <p><a href="http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar13.html">http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_mar13.html</a></p><br /> Thu, 2013 April 11 08:42:13 PDT