CVE-2007-5537
published 2007-10-18CVE-2007-5537: Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of…
PriorityP431high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.98%
78.3th percentile
Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_communications_manager | <= 5.1\(2\) | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2007-10-17·CVSS 10.0
CVE-2007-5537 [CRITICAL] CWE-119 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly CallManager,
contains two denial of service (DoS) vulnerabilities. Large volumes of UDP
Session Initiation Protocol (SIP) INVITE messages may cause a resource
exhaustion condition on CUCM systems resulting in a kernel panic. The CUCM
Trivial File Transfer Protocol (TFTP) service contains a buffer overflow
vulnerability that may result in a denial of service condition or allow a
remote, unauthenticated user to execute arbitrary code. There are no
workarounds for these vulnerabilities.
Cisco has made free software available to address these vulnerabilities
for affected customers.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoS
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2007-5537 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2007-5537: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly CallManager, contains two denial of service (DoS) vulnerabilities. Large volumes of UDP Session Initiation Protocol (SIP) INVITE messages may cause a resource exhaustion condition on CUCM systems resulting in a kernel panic. The CUCM Trivial File Transfer Protocol (TFTP) service contains a buffer overflow vulnerability that may result in a denial of service condition or allow a remote, unauthenticated user to execute arbitrary code. There are no
CWE: CWE-119, CWE-399, CWE-119, CWE-399
Bug IDs: CSCsi75822, CSCsh47712
GHSA
GHSA-62w5-fwxx-rpgg: Cisco Unified Communications Manager (CUCM, formerly CallManager) 5
ghsa_unreviewed·2022-05-01
CVE-2007-5537 [HIGH] GHSA-62w5-fwxx-rpgg: Cisco Unified Communications Manager (CUCM, formerly CallManager) 5
Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/37941http://secunia.com/advisories/27296http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda34.shtmlhttp://www.securityfocus.com/bid/26105http://www.securitytracker.com/id?1018828http://www.vupen.com/english/advisories/2007/3532https://exchange.xforce.ibmcloud.com/vulnerabilities/37246http://osvdb.org/37941http://secunia.com/advisories/27296http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda34.shtmlhttp://www.securityfocus.com/bid/26105http://www.securitytracker.com/id?1018828http://www.vupen.com/english/advisories/2007/3532https://exchange.xforce.ibmcloud.com/vulnerabilities/37246
2007-10-18
Published