CVE-2009-2050
published 2009-08-27CVE-2009-2050: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.44%
87.6th percentile
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | < 6.1\(1\) | 6.1\(1\) |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2009-08-26·CVSS 7.8
CVE-2009-2050 [HIGH] CWE-399 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains
multiple denial of service (DoS) vulnerabilities that if exploited could cause
an interruption to voice services. The Session Initiation Protocol (SIP) and
Skinny Client Control Protocol (SCCP) services are affected by these
vulnerabilities.
Cisco has released free software updates for select Cisco Unified
Communications Manager versions that address these vulnerabilities. There are
no workarounds for these vulnerabilities.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090826-cucm.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2009-2050 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2009-2050: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption to voice services. The Session Initiation Protocol (SIP) and Skinny Client Control Protocol (SCCP) services are affected by these vulnerabilities. Cisco has released free software updates for select Cisco Unified Communications Manager versions that address these vulnerabilities. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsz43987, CSCta20040, CSCtf72678, CSCsi46466, CSCsz40392
GHSA
GHSA-52wx-6vvh-8hww: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6
ghsa_unreviewed·2022-05-02
CVE-2009-2050 [HIGH] GHSA-52wx-6vvh-8hww: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/57452http://secunia.com/advisories/36495http://secunia.com/advisories/36499http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.securityfocus.com/bid/36152http://www.securitytracker.com/id?1022775http://osvdb.org/57452http://secunia.com/advisories/36495http://secunia.com/advisories/36499http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.securityfocus.com/bid/36152http://www.securitytracker.com/id?1022775
2009-08-27
Published