CVE-2008-2061
published 2008-06-26CVE-2008-2061: The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.45%
82.6th percentile
The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | >= 5.0 < 5.1\(3c\) | 5.1\(3c\) |
| cisco | unified_communications_manager | >= 6.0 < 6.1\(2\) | 6.1\(2\) |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
vendor_cisco·2008-06-25·CVSS 7.8
CVE-2008-2061 [HIGH] CWE-200 Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly Cisco
CallManager, contains a denial of service (DoS) vulnerability in the Computer
Telephony Integration (CTI) Manager service that may cause an interruption in
voice services and an authentication bypass vulnerability in the Real-Time
Information Server (RIS) Data Collector that may expose information that is
useful for reconnaissance.
Cisco has released software updates that address these vulnerabilities. There are no workarounds for these vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20080625-cucm.
Cisco
Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
vendor_cisco
CVE-2008-2061 Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
CVE-2008-2061: Cisco Unified Communications Manager Denial of Service and Authentication Bypass Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Computer Telephony Integration (CTI) Manager service that may cause an interruption in voice services and an authentication bypass vulnerability in the Real-Time Information Server (RIS) Data Collector that may expose information that is useful for reconnaissance. Cisco has released software updates that address these vulnerabilities. There are no
CWE: CWE-200, CWE-399, CWE-200, CWE-399
Bug IDs: CSCso75027, CSCsq35151, CSCsj90843, CSCso75027, CSCsq35151
GHSA
GHSA-prvr-fvg6-m8jr: The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2008-2061 [HIGH] CWE-20 GHSA-prvr-fvg6-m8jr: The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5
The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/30848http://www.cisco.com/en/US/products/products_security_advisory09186a00809b9011.shtmlhttp://www.securityfocus.com/bid/29933http://www.securitytracker.com/id?1020360http://www.vupen.com/english/advisories/2008/1933/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43349http://secunia.com/advisories/30848http://www.cisco.com/en/US/products/products_security_advisory09186a00809b9011.shtmlhttp://www.securityfocus.com/bid/29933http://www.securitytracker.com/id?1020360http://www.vupen.com/english/advisories/2008/1933/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43349
2008-06-26
Published