Multiple Vulnerabilities in Cisco PGW Softswitch

Related Vulnerabilities: CVE-2010-0601   CVE-2010-0602   CVE-2010-0603   CVE-2010-0604   CVE-2010-1561   CVE-2010-1562   CVE-2010-1563   CVE-2010-1565   CVE-2010-1567  

Multiple vulnerabilities exist in the Cisco PGW 2200 Softswitch series of products. Each vulnerability described in this advisory is independent from other. The vulnerabilities are related to processing Session Initiation Protocol (SIP) or Media Gateway Control Protocol (MGCP) messages. Successful exploitation of all but one of these vulnerabilities can crash the affected device. Exploitation of the remaining vulnerability will not crash the affected device, but it can lead to a denial-of-service (DoS) condition in which no new TCP-based connections will be accepted or created. Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities. This advisory is posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100512-pgw.