Executive Summary

Summary
Title Cisco Unified Communications Manager Denial of Service Vulnerabilities
Informations
Name cisco-sa-20080514-cucmdos First vendor Publication 2008-03-31
Vendor Cisco Last vendor Modification 2012-02-01
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C)
Cvss Base Score 7.8 Attack Range Network
Cvss Impact Score 6.9 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cisco Unified Communications Manager, formerly Cisco CallManager, contains multiple denial of service (DoS) vulnerabilities that may cause an interruption in voice services, if exploited. These vulnerabilities were discovered internally by Cisco. The following Cisco Unified Communications Manager services are affected:

* Certificate Trust List (CTL) Provider
* Certificate Authority Proxy Function (CAPF)
* Session Initiation Protocol (SIP)
* Simple Network Management Protocol (SNMP) Trap

Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.

Original Source

Url : http://www.cisco.com/en/US/products/products_security_advisory09186a008099 (...)

CWE : Common Weakness Enumeration

% Id Name
71 % CWE-20 Improper Input Validation
29 % CWE-399 Resource Management Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 5
Application 117

Open Source Vulnerability Database (OSVDB)

Id Description
45209 Cisco Unified Communications Manager Certificate Trust List (CTL) Provider Se...

45208 Cisco Unified Communications Manager Certificate Trust List (CTL) Provider Se...

45207 Cisco Unified Communications Manager Certificate Authority Proxy Function (CA...

45206 Cisco Unified Communications Manager SIP JOIN Message Handling Remote DoS

45205 Cisco Unified Communications Manager SNMP Trap Agent Service Malformed UDP Pa...

45204 Cisco Unified Communications Manager SIP INVITE Handling Remote DoS (CSCsk46944)

45203 Cisco Unified Communications Manager SIP INVITE Handling Remote DoS (CSCsl22355)