CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:N/I:N/A:C
AI Score
Confidence
High
EPSS
Percentile
82.8%
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | unified_communications_manager | 6.0(1a) | cpe:2.3:a:cisco:unified_communications_manager:6.0\(1a\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.0(1b) | cpe:2.3:a:cisco:unified_communications_manager:6.0\(1b\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(1) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(1\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(1a) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(1a\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(1b) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(1b\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(2) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(2\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(3) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(3\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(3a) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(3a\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(3b) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(3b\):*:*:*:*:*:*:* |
cisco | unified_communications_manager | 6.1(4) | cpe:2.3:a:cisco:unified_communications_manager:6.1\(4\):*:*:*:*:*:*:* |