CVE-2018-0086 describes a denial-of-service (DoS) vulnerability in Cisco Unified Customer Voice Portal (CVP) versions prior to 11.6(1). An unauthenticated, remote attacker can exploit this by sending specially crafted, malformed SIP INVITE traffic to the CVP, particularly during communication with Cisco Virtualized Voice Browser (VVB). This vulnerability carries a CVSSv3 score of 8.6 (HIGH), indicating a critical impact on availability (A:H) with no user interaction required (UI:N) and low attack complexity (AC:L). The attack vector is network-based (AV:N), allowing remote exploitation without authentication (PR:N). While there is no known active exploitation (KEV: No) or public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.5CPE matchmatch criteria | cpe:2.3:a:cisco:unified_customer_voice_portal:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.