CVE-2008-1748
published 2008-05-16CVE-2008-1748: Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.45%
82.7th percentile
Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | >= 4.1 < 4.1\(3\)sr7 | 4.1\(3\)sr7 |
| cisco | unified_communications_manager | >= 4.2 < 4.2\(3\)sr4 | 4.2\(3\)sr4 |
| cisco | unified_communications_manager | >= 4.3 < 4.3\(2\) | 4.3\(2\) |
| cisco | unified_communications_manager | >= 5.0 < 5.1\(3\) | 5.1\(3\) |
| cisco | unified_communications_manager | >= 6.0 < 6.1\(1\) | 6.1\(1\) |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2008-05-14·CVSS 7.8
CVE-2008-1742 [HIGH] CWE-399 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager, formerly Cisco CallManager,
contains multiple denial of service (DoS) vulnerabilities that may cause an
interruption in voice services, if exploited. These vulnerabilities were
discovered internally by Cisco. The following Cisco Unified Communications
Manager services are affected:
Certificate Trust List (CTL) Provider
Certificate Authority Proxy Function (CAPF)
Session Initiation Protocol (SIP)
Simple Network Management Protocol (SNMP) Trap
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are
available.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecuri
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2008-1748 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2008-1748: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager, formerly Cisco CallManager, contains multiple denial of service (DoS) vulnerabilities that may cause an interruption in voice services, if exploited. These vulnerabilities were discovered internally by Cisco. The following Cisco Unified Communications Manager services are affected: Certificate Trust List (CTL) Provider Certificate Authority Proxy Function (CAPF) Session Initiation Protocol (SIP) Simple Network Management Protocol (SNMP) Trap Cisco has released software updates that address these vulnerabilities.
CWE: CWE-399, CWE-399
Bug IDs: CSCsj80609, CSCsi98433, CSCsk46770, CSCsi48115, CSCsk46944
GHSA
GHSA-3pw9-xq5q-xv5f: Cisco Unified Communications Manager 4
ghsa_unreviewed·2022-05-01
CVE-2008-1748 [HIGH] CWE-20 GHSA-3pw9-xq5q-xv5f: Cisco Unified Communications Manager 4
Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/30238http://securitytracker.com/id?1020022http://www.cisco.com/en/US/products/products_security_advisory09186a0080995688.shtmlhttp://www.securityfocus.com/bid/29221http://www.vupen.com/english/advisories/2008/1533https://exchange.xforce.ibmcloud.com/vulnerabilities/42419http://secunia.com/advisories/30238http://securitytracker.com/id?1020022http://www.cisco.com/en/US/products/products_security_advisory09186a0080995688.shtmlhttp://www.securityfocus.com/bid/29221http://www.vupen.com/english/advisories/2008/1533https://exchange.xforce.ibmcloud.com/vulnerabilities/42419
2008-05-16
Published