cbcvebase.
CVE-2008-1748
published 2008-05-16

CVE-2008-1748: Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly…

PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.45%
82.7th percentile
Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscounified_communications_manager
ciscounified_communications_manager>= 4.1 < 4.1\(3\)sr74.1\(3\)sr7
ciscounified_communications_manager>= 4.2 < 4.2\(3\)sr44.2\(3\)sr4
ciscounified_communications_manager>= 4.3 < 4.3\(2\)4.3\(2\)
ciscounified_communications_manager>= 5.0 < 5.1\(3\)5.1\(3\)
ciscounified_communications_manager>= 6.0 < 6.1\(1\)6.1\(1\)

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.