This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:cisco:unified_communications_manager:5.1_1 |
| Detail | |||
|---|---|---|---|
| Vendor | Cisco | First view | 2008-05-16 |
| Product | Unified Communications Manager | Last view | 2009-08-27 |
| Version | 5.1_1 | Type | Application |
| Edition | |||
| Language | |||
| Update | |||
| CPE Product | cpe:/a:cisco:unified_communications_manager | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 7.8 | 2009-08-27 | CVE-2009-2054 | Network | Low | None Requ... | |
| 7.8 | 2009-08-27 | CVE-2009-2053 | Network | Low | None Requ... | |
| 7.8 | 2009-08-27 | CVE-2009-2052 | Network | Low | None Requ... | |
| 7.8 | 2009-08-27 | CVE-2009-2051 | Network | Low | None Requ... | |
| 7.8 | 2009-08-27 | CVE-2009-2050 | Network | Low | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2009-01-22 | CVE-2009-0057 | Network | Medium | None Requ... | |
| 7.8 | 2008-05-16 | CVE-2008-1744 | Network | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 100% (2) | CWE-20 | Improper Input Validation |
CAPEC : Common Attack Pattern Enumeration & Classificatio
| id | Name |
|---|---|
| CAPEC-2 | Inducing Account Lockout |
| CAPEC-82 | Violating Implicit Assumptions Regarding XML Content (aka XML Denial of Servi... |
| CAPEC-99 | XML Parser Attack |
| CAPEC-119 | Resource Depletion |
| CAPEC-121 | Locate and Exploit Test APIs |
| id | Name |
|---|---|
| CAPEC-125 | Resource Depletion through Flooding |
| CAPEC-130 | Resource Depletion through Allocation |
| CAPEC-147 | XML Ping of Death |
| CAPEC-197 | XEE (XML Entity Expansion) |
| CAPEC-227 | Denial of Service through Resource Depletion |
| CAPEC-228 | Resource Depletion through DTD Injection in a SOAP Message |
| CAPEC-229 | XML Attribute Blowup |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 57456 | Cisco Unified Communications Manager SIP Packet Processing Unspecified Remote... |
| 57455 | Cisco Unified Communications Manager SCCP Packet Handling Unspecified Remote DoS |
| 57454 | Cisco Unified Communications Manager Embedded Firewall Network Connection Sat... |
| 57453 | Cisco Unified Communications Manager SIP Trunk Malformed Packet Handling Remo... |
| 57452 | Cisco Unified Communications Manager Unspecified SIP Packet Handling Remote DoS |
| id | Description |
|---|---|
| 52317 | Cisco Unified Communications Manager Certificate Authority Proxy Function (CA... |
| 45207 | Cisco Unified Communications Manager Certificate Authority Proxy Function (CA... |









