CVE-2009-2051
published 2009-08-27CVE-2009-2051: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly…
PriorityP336high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.44%
87.6th percentile
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | 12.2 – 12.4 | — |
| cisco | ios | 15.0 – 15.1 | — |
| cisco | ios_xe | 2.5.0 – 2.6.1 | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | >= 5.0 < 5.1\(3g\) | 5.1\(3g\) |
| cisco | unified_communications_manager | >= 6.1\(1\) < 6.1\(4\) | 6.1\(4\) |
| cisco | unified_communications_manager | >= 7.1 < 7.1\(2\) | 7.1\(2\) |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco·2010-09-22·CVSS 7.8
CVE-2009-2051 [HIGH] CWE-399 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP)
implementation in Cisco IOS® Software that could
allow an unauthenticated, remote attacker to cause a reload of an affected
device when SIP operation is enabled.
Cisco has released software updates that address these vulnerabilities. There are no workarounds for devices that must run SIP;
however, mitigations are available to limit exposure to the
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100922-sip.
Note: The September 22, 2010, Cisco IOS Software Security Advisory bundled
publication includes six Cisco Security Advisories. Five of the advisories
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2009-08-26·CVSS 7.8
CVE-2009-2050 [HIGH] CWE-399 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains
multiple denial of service (DoS) vulnerabilities that if exploited could cause
an interruption to voice services. The Session Initiation Protocol (SIP) and
Skinny Client Control Protocol (SCCP) services are affected by these
vulnerabilities.
Cisco has released free software updates for select Cisco Unified
Communications Manager versions that address these vulnerabilities. There are
no workarounds for these vulnerabilities.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090826-cucm.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2009-2051 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2009-2051: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption to voice services. The Session Initiation Protocol (SIP) and Skinny Client Control Protocol (SCCP) services are affected by these vulnerabilities. Cisco has released free software updates for select Cisco Unified Communications Manager versions that address these vulnerabilities. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsz43987, CSCta20040, CSCtf72678, CSCsi46466, CSCsz40392
GHSA
GHSA-mp73-2m32-64h6: Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-2051 [HIGH] GHSA-mp73-2m32-64h6: Cisco IOS 12
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/57453http://secunia.com/advisories/36498http://secunia.com/advisories/36499http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080b4a30f.shtmlhttp://www.securityfocus.com/bid/36152http://www.securitytracker.com/id?1022775http://osvdb.org/57453http://secunia.com/advisories/36498http://secunia.com/advisories/36499http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080b4a30f.shtmlhttp://www.securityfocus.com/bid/36152http://www.securitytracker.com/id?1022775
2009-08-27
Published