Lucene search

K
ciscoCiscoCISCO-SA-20081009-CVE-2008-4544
HistoryOct 09, 2008 - 1:53 p.m.

Cisco Unity Connection Exhaustion Denial of Service Vulnerability

2008-10-0913:53:41
tools.cisco.com
11

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.012

Percentile

85.1%

Cisco Unity contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.

This vulnerability exists due to improper handling of network messages. An unauthenticated, remote attacker to exploit this vulnerability to render the Cisco Unity server unavailable, which may deny legitimate users access to the affected system.

Cisco confirmed this vulnerability, but updated software is not available.

Attackers may require access to trusted, internal networks to connect to an affected system. An exploit could prevent the establishment of further connections with the affected system. This denial of service condition could prevent users from accessing the Cisco Unity server.

Affected configurations

Vulners
Node
ciscounityMatchany
OR
ciscounityMatchany
VendorProductVersionCPE
ciscounityanycpe:2.3:a:cisco:unity:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.012

Percentile

85.1%

Related for CISCO-SA-20081009-CVE-2008-4544