CVE-2009-2052Cisco Unified Communications Manager vulnerability

CWE-3997 documents5 sources
Severity
7.8HIGHNVD
EPSS
2.8%
top 13.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 27
Latest updateMay 2

Description

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "tracking of network connections," aka Bug IDs CSCsq22534 and CSCsw52371.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

NVDcisco/unified_communications_manager5.05.1\(3g\)+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qj8c-mx4x-hh37: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 42022-05-02
CVEList
CVE-2009-2052: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 42009-08-27

💥Exploits & PoCs

3
Exploit-DB
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (1)2009-01-04
Exploit-DB
Destiny Media Player 1.61 - '.m3u' Local Stack Overflow2009-01-03
Exploit-DB
Destiny Media Player 1.61 - '.lst' Local Buffer Overflow (PoC)2009-01-03

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities2009-08-26
CVE-2009-2052 — Cisco vulnerability | cvebase