CVE-2017-6779 Details
Description
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maximum size restriction. Therefore, the file is allowed to consume the majority of available disk space on the appliance. An attacker could exploit this vulnerability by sending crafted remote connection requests to the appliance. Successful exploitation could allow the attacker to increase the size of a system log file so that it consumes most of the disk space. The lack of available disk space could lead to a DoS condition in which the application functions could operate abnormally, making the appliance unstable. This vulnerability affects the following Cisco Voice Operating System (VOS)-based products: Emergency Responder, Finesse, Hosted Collaboration Mediation Fulfillment, MediaSense, Prime License Manager, SocialMiner, Unified Communications Manager (UCM), Unified Communications Manager IM and Presence Service (IM&P - earlier releases were known as Cisco Unified Presence), Unified Communication Manager Session Management Edition (SME), Unified Contact Center Express (UCCx), Unified Intelligence Center (UIC), Unity Connection, Virtualized Voice Browser. This vulnerability also affects Prime Collaboration Assurance and Prime Collaboration Provisioning. Cisco Bug IDs: CSCvd10872, CSCvf64322, CSCvf64332, CSCvi29538, CSCvi29543, CSCvi29544, CSCvi29546, CSCvi29556, CSCvi29571, CSCvi31738, CSCvi31741, CSCvi31762, CSCvi31807, CSCvi31818, CSCvi31823.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 29, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-diskdos | CVE | Vendor Advisory |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180606-diskdos | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-399 | Resource Management Errors | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco emergency responder | >= 10.5, < 10.5\(1a\) >= 11.0, < 11.5\(4\) >= 12.0, < 12.0su1 11.0(1.10000.10) |
CPE
Remediation
| |
| cisco finesse | >= 11.5, < 11.5\(3\) 9.5(1) |
CPE
Remediation
| |
| cisco hosted collaboration mediation fulfillment | >= 11.5, < 11.5\(3\) 9.5(1) |
CPE
Remediation
| |
| cisco mediasense | >= 11.5, < 11.5su2 9.5(1) |
CPE
Remediation
| |
| cisco prime collaboration assurance | >= 11.6, < 11.6_es16 >= 12.1, < 12.1_es2 |
CPE
Remediation
| |
| cisco prime collaboration provisioning | 12.5 |
CPE
Remediation
| |
| cisco prime license manager | >= 10.5, < 10.5.2 >= 11.0, < 11.5\(1\)su5 |
CPE
Remediation
| |
| cisco socialminer | >= 11.6, < 11.6.1 |
CPE
Remediation
| |
| cisco unified communications manager | >= 10.0, < 10.5\(2\)su5 >= 11.0, < 11.0\(1a\)su4 >= 11.5, < 11.5\(1\)su3 10.5(2.10000.5) 11.0(1.10000.10) 11.5(1.10000.6) 12.0 |
CPE
Remediation
| |
| cisco unified contact center express | >= 11.6, < 11.6\(1\) 9.0(2)su1.3 |
CPE
Remediation
| |
| cisco unified intelligence center | >= 11.6, < 11.6\(1\) 9.5(1) |
CPE
Remediation
| |
| cisco unity connection | >= 10.5, < 10.5su5 >= 11.0, < 11.5.1su3 9.5(0.9)tt0 12.0 |
CPE
Remediation
| |
| cisco virtualized voice browser | >= 11.6, < 11.6\(1\) |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | CPE Deprecation Remap | [email protected] |
| Jul 31, 2025 | CPE Deprecation Remap | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Jul 23, 2018 | Initial Analysis | [email protected] |