<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sig Name: CUCM CTI DoS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sig-name-cucm-cti-dos/m-p/1457850#M67025</link>
    <description>&lt;P&gt;I am seeing Sig ID: 6799 Subsig 0 a lot on our 4215.&lt;/P&gt;&lt;P&gt;Sig Name: CUCM CTI DoS&lt;BR /&gt;Sig ID: 6799&lt;BR /&gt;Severity: Medium&lt;BR /&gt;Risk Rating: 66&lt;BR /&gt;Sig Version: S448&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for more information regarding this alert, is this flase positive?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:02:56 GMT</pubDate>
    <dc:creator>FIS-Global FIS-ProNet</dc:creator>
    <dc:date>2019-03-10T12:02:56Z</dc:date>
    <item>
      <title>Sig Name: CUCM CTI DoS</title>
      <link>https://community.cisco.com/t5/network-security/sig-name-cucm-cti-dos/m-p/1457850#M67025</link>
      <description>&lt;P&gt;I am seeing Sig ID: 6799 Subsig 0 a lot on our 4215.&lt;/P&gt;&lt;P&gt;Sig Name: CUCM CTI DoS&lt;BR /&gt;Sig ID: 6799&lt;BR /&gt;Severity: Medium&lt;BR /&gt;Risk Rating: 66&lt;BR /&gt;Sig Version: S448&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for more information regarding this alert, is this flase positive?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-name-cucm-cti-dos/m-p/1457850#M67025</guid>
      <dc:creator>FIS-Global FIS-ProNet</dc:creator>
      <dc:date>2019-03-10T12:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Name: CUCM CTI DoS</title>
      <link>https://community.cisco.com/t5/network-security/sig-name-cucm-cti-dos/m-p/1457851#M67028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The best place to begin research on Cisco IPS signature issues is the Cisco IntelliShield site:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/security"&gt;http://www.cisco.com/security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this specific signature, the details are outlined here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=6799&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S448"&gt;http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=6799&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S448&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Details of the exploit detected are outlined here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/viewAlert.x?alertId=16136"&gt;http://tools.cisco.com/security/center/viewAlert.x?alertId=16136&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without being able to see the traffic which triggered the signature it will not be possible to determine whether this is a false positivie or not.&amp;nbsp; Specific network conditions will assist more accurately determining the validity of the event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jul 2010 18:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-name-cucm-cti-dos/m-p/1457851#M67028</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-07-02T18:26:22Z</dc:date>
    </item>
  </channel>
</rss>

