Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15396

Опубликовано: 05 окт. 2018
Источник: nvd
CVSS3: 6.8
CVSS2: 4
EPSS Низкий

Описание

A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software does not restrict the maximum size of certain files that can be written to disk. An attacker who has valid administrator credentials for an affected system could exploit this vulnerability by sending a crafted, remote connection request to an affected system. A successful exploit could allow the attacker to write a file that consumes most of the available disk space on the system, causing application functions to operate abnormally and leading to a DoS condition.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:unity_connection:12.5:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00613
Низкий

6.8 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-399
CWE-400

Связанные уязвимости

CVSS3: 6.8
github
больше 3 лет назад

A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software does not restrict the maximum size of certain files that can be written to disk. An attacker who has valid administrator credentials for an affected system could exploit this vulnerability by sending a crafted, remote connection request to an affected system. A successful exploit could allow the attacker to write a file that consumes most of the available disk space on the system, causing application functions to operate abnormally and leading to a DoS condition.

EPSS

Процентиль: 69%
0.00613
Низкий

6.8 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-399
CWE-400