CVE-2009-2054
published 2009-08-27CVE-2009-2054: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.40%
87.5th percentile
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | >= 4.0 < 5.1\(3g\) | 5.1\(3g\) |
| cisco | unified_communications_manager | >= 6.0 < 6.1\(4\) | 6.1\(4\) |
| cisco | unified_communications_manager | >= 7.0 < 7.0\(2a\)su1 | 7.0\(2a\)su1 |
| cisco | unified_communications_manager | >= 7.1 < 7.1\(2a\)su1 | 7.1\(2a\)su1 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2009-08-26·CVSS 7.8
CVE-2009-2050 [HIGH] CWE-399 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains
multiple denial of service (DoS) vulnerabilities that if exploited could cause
an interruption to voice services. The Session Initiation Protocol (SIP) and
Skinny Client Control Protocol (SCCP) services are affected by these
vulnerabilities.
Cisco has released free software updates for select Cisco Unified
Communications Manager versions that address these vulnerabilities. There are
no workarounds for these vulnerabilities.
This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090826-cucm.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2009-2054 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2009-2054: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption to voice services. The Session Initiation Protocol (SIP) and Skinny Client Control Protocol (SCCP) services are affected by these vulnerabilities. Cisco has released free software updates for select Cisco Unified Communications Manager versions that address these vulnerabilities. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsz43987, CSCta20040, CSCtf72678, CSCsi46466, CSCsz40392
GHSA
GHSA-4p6p-3h4p-27fp: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4
ghsa_unreviewed·2022-05-02
CVE-2009-2054 [HIGH] CWE-770 GHSA-4p6p-3h4p-27fp: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Uncontrolled Resource Consumption
mitre_cwe
CWE-400 Uncontrolled Resource Consumption
CWE-400: Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Modes of Introduction:
Phase: Operation
Note: The product could be operated in a system or environment with lower resource limits than expected, which might make it easier for attackers to consume all available resources.
Phase: System Configuration
Note: The product could be configured with lower resource limits than expected, which might make it easier for attackers to consume all available resources.
Phase: Architecture and Design
Note: The designer might not consider how to handle and throttle excessive resource requests, which typically requires careful planning to handle more gracefully than a crash or exit.
Phase: Implementation
Note: There are at
CWE
Missing Release of Resource after Effective Lifetime
mitre_cwe
CWE-772 Missing Release of Resource after Effective Lifetime
CWE-772: Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Availability. Impact: DoS: Resource Consumption (Other), DoS: Resource Consumption (Memory), DoS: Resource Consumption (CPU). An attacker that can influence the allocation of resources that are not properly released could deplete the available resource pool and prevent all other processes from accessing the same type of resource. Frequently-affected resources include memory, CPU, disk space, power or battery, etc.
Detection Methods:
Automated Static Analysis: Automated static analysis, commonly referred to as Static Application S
CWE
Allocation of Resources Without Limits or Throttling
mitre_cwe
CWE-770 Allocation of Resources Without Limits or Throttling
CWE-770: Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Modes of Introduction:
Phase: Architecture and Design
Note: OMISSION: This weakness is caused by missing a security tactic during the architecture and design phase.
Phase: Implementation
Phase: Operation
Phase: System Configuration
Common Consequences:
Scope: Availability. Impact: DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other). When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be
http://osvdb.org/57456http://secunia.com/advisories/36498http://secunia.com/advisories/36499http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.securityfocus.com/bid/36152http://www.securitytracker.com/id?1022775http://osvdb.org/57456http://secunia.com/advisories/36498http://secunia.com/advisories/36499http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtmlhttp://www.securityfocus.com/bid/36152http://www.securitytracker.com/id?1022775
2009-08-27
Published