Lucene search

K
cveCiscoCVE-2016-1466
HistoryAug 08, 2016 - 12:59 a.m.

CVE-2016-1466

2016-08-0800:59:05
CWE-399
cisco
web.nvd.nist.gov
26
cve-2016-1466
cisco
unified communications manager
im
presence service
denial of service
vulnerability

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.006

Percentile

77.8%

Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packet, aka Bug ID CSCva39072.

Affected configurations

Nvd
Node
ciscounified_communications_manager_im_and_presence_serviceMatch9.1\(1\)
OR
ciscounified_communications_manager_im_and_presence_serviceMatch10.5\(2\)
OR
ciscounified_communications_manager_im_and_presence_serviceMatch11.0\(1\)
OR
ciscounified_communications_manager_im_and_presence_serviceMatch11.5\(1\)
VendorProductVersionCPE
ciscounified_communications_manager_im_and_presence_service9.1(1)cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:9.1\(1\):*:*:*:*:*:*:*
ciscounified_communications_manager_im_and_presence_service10.5(2)cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5\(2\):*:*:*:*:*:*:*
ciscounified_communications_manager_im_and_presence_service11.0(1)cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.0\(1\):*:*:*:*:*:*:*
ciscounified_communications_manager_im_and_presence_service11.5(1)cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5\(1\):*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.006

Percentile

77.8%

Related for CVE-2016-1466