CVE-2009-0057
published 2009-01-22CVE-2009-0057: The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
0.89%
55.7th percentile
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mcx4-vf2j-97x9: The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5
ghsa_unreviewed·2022-05-02
CVE-2009-0057 [MEDIUM] CWE-20 GHSA-mcx4-vf2j-97x9: The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."
Cisco
Cisco Unified Communications Manager CAPF Denial of Service Vulnerability
vendor_cisco·2009-01-21·CVSS 7.8
CVE-2009-0057 [HIGH] CWE-399 Cisco Unified Communications Manager CAPF Denial of Service Vulnerability
Cisco Unified Communications Manager CAPF Denial of Service Vulnerability
Cisco Unified Communications Manager, formerly Cisco CallManager,
contains a denial of service (DoS) vulnerability in the Certificate Authority
Proxy Function (CAPF) service. Exploitation of this vulnerability could cause
an interruption in voice services. The CAPF service is disabled by
default.
Cisco has released software updates that address this vulnerability. Workarounds available that mitigate this vulnerability are
available.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090121-cucmcapf.
Cisco
Cisco Unified Communications Manager CAPF Denial of Service Vulnerability
vendor_cisco
CVE-2009-0057 Cisco Unified Communications Manager CAPF Denial of Service Vulnerability
CVE-2009-0057: Cisco Unified Communications Manager CAPF Denial of Service Vulnerability
Cisco Unified Communications Manager, formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Certificate Authority Proxy Function (CAPF) service. Exploitation of this vulnerability could cause an interruption in voice services. The CAPF service is disabled by default. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCsq32032
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/33588http://www.cisco.com/en/US/products/products_security_advisory09186a0080a61928.shtmlhttp://www.securityfocus.com/bid/33379http://www.securitytracker.com/id?1021620http://www.vupen.com/english/advisories/2009/0213https://exchange.xforce.ibmcloud.com/vulnerabilities/48139http://secunia.com/advisories/33588http://www.cisco.com/en/US/products/products_security_advisory09186a0080a61928.shtmlhttp://www.securityfocus.com/bid/33379http://www.securitytracker.com/id?1021620http://www.vupen.com/english/advisories/2009/0213https://exchange.xforce.ibmcloud.com/vulnerabilities/48139
2009-01-22
Published