Executive Summary

Summary
Title Multiple Cisco Unified CallManager and Presence Server Denial of Service Vulnerabilities
Informations
Name cisco-sa-20070328-voip First vendor Publication 2007-03-02
Vendor Cisco Last vendor Modification 2007-03-26
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.8 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cisco Unified CallManager (CUCM) and Cisco Unified Presence Server (CUPS) contain multiple vulnerabilities which may result in the failure of CUCM or CUPS functionality, resulting in a Denial of Service (DoS) condition. There are no workarounds for these vulnerabilities. Cisco has made free software available to address these vulnerabilities for affected customers.

Original Source

Url : http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtml

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 25
Application 3

Open Source Vulnerability Database (OSVDB)

Id Description
34919 Cisco Multiple Products Crafted UDP Packet Remote DoS

34595 Cisco Unified CallManager (CUCM) Skinny Call Control Protocol (SCCP) Crafted ...

34594 Cisco CUCM / CUPS ICMP Echo Request Saturation DoS

Cisco CUCM and Cisco CUPS both contain a flaw that may allow a remote denial of service. The issue is triggered when ICMP Echo Request packets are repeatedly sent, and will result in loss of availability for the service.