CVE-2007-1834
published 2007-04-03CVE-2007-1834: Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.92%
77.6th percentile
Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_presence_server | — | — |
| cisco | unified_presence_server | — | — |
| cisco | unified_presence_server | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified CallManager and Unified Presence Server ICMP Echo Request Handling Denial of Service Vulnerability
vendor_cisco·2007-03-28·CVSS 7.8
CVE-2007-1834 [HIGH] CWE-399 Cisco Unified CallManager and Unified Presence Server ICMP Echo Request Handling Denial of Service Vulnerability
Cisco Unified CallManager and Unified Presence Server ICMP Echo Request Handling Denial of Service Vulnerability
Cisco Unified CallManager and Unified Presence Server contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability exists due to improper handling of excessive amounts of ICMP echo requests. An attacker could exploit this vulnerability by sending a large number of ICMP echo requests to a CallManager or Presence Server system. These requests may cause various services to crash, resulting in a DoS condition and affecting voice services.
Cisco confirmed this vulnerability in a security advisory and released updates.
Cisco Unified CallManager is the call-processing component of the Cisco IP telephony so
GHSA
GHSA-wx8m-8vvg-mg6w: Cisco Unified CallManager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2007-1834 [HIGH] GHSA-wx8m-8vvg-mg6w: Cisco Unified CallManager (CUCM) 5
Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/24690http://securitytracker.com/id?1017826http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtmlhttp://www.securityfocus.com/bid/23181http://www.vupen.com/english/advisories/2007/1144https://exchange.xforce.ibmcloud.com/vulnerabilities/33299http://secunia.com/advisories/24690http://securitytracker.com/id?1017826http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtmlhttp://www.securityfocus.com/bid/23181http://www.vupen.com/english/advisories/2007/1144https://exchange.xforce.ibmcloud.com/vulnerabilities/33299
2007-04-03
Published