Lucene search

K
ciscoCiscoCISCO-SA-20130515-CVE-2013-1188
HistoryMay 15, 2013 - 8:12 p.m.

Cisco Unified Communications Manager Authentication Denial of Service Vulnerability

2013-05-1520:12:18
tools.cisco.com
15

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.001

Percentile

49.5%

A vulnerability in device authentication of Cisco Unified Communications Manager (CUCM) could allow an unauthenticated, remote attacker to impact application response.

The vulnerability is due to incomplete throttling of authentication requests. An attacker could exploit this vulnerability by sending multiple authentication requests in a short period of time. An exploit could allow the attacker to degrade the performance of the CUCM application.

Cisco has confirmed the vulnerability in a security notice and has released software updates.

To exploit this vulnerability, an attacker may require access to a trusted, internal network to send authentication requests to the targeted system. This access requirement could limit the likelihood of a successful exploit.

Customers are advised to review the bug report in the “Vendor Announcements” section for a current list of affected versions.

Affected configurations

Vulners
Node
ciscounified_communications_managerMatchany
OR
ciscounified_communications_managerMatchany
VendorProductVersionCPE
ciscounified_communications_manageranycpe:2.3:a:cisco:unified_communications_manager:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.001

Percentile

49.5%

Related for CISCO-SA-20130515-CVE-2013-1188