CVE-2009-2864
published 2009-09-28CVE-2009-2864: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2)…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.94%
85.6th percentile
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2009-09-23·CVSS 7.8
CVE-2009-2864 [HIGH] CWE-399 Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
Cisco Unified Communications Manager, which was formerly Cisco Unified
CallManager, contains a denial of service (DoS) vulnerability in the Session
Initiation Protocol (SIP) service. An exploit of this vulnerability may cause
an interruption in voice services.
Cisco has released software updates that address this vulnerability. There are no workarounds for this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-cm.
Note: Cisco IOS® Software is also affected by
the vulnerability described in this advisory. A companion advisory for Cisco
IOS software is available at
https://sec.cloudapps.cisco.com/security/
Cisco
Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco
CVE-2009-2864 Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
CVE-2009-2864: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
Cisco Unified Communications Manager, which was formerly Cisco Unified CallManager, contains a denial of service (DoS) vulnerability in the Session Initiation Protocol (SIP) service. An exploit of this vulnerability may cause an interruption in voice services. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCsz95423
GHSA
GHSA-mf92-5j9q-wjfr: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5
ghsa_unreviewed·2022-05-02
CVE-2009-2864 [HIGH] GHSA-mf92-5j9q-wjfr: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/58344http://secunia.com/advisories/36836http://tools.cisco.com/security/center/viewAlert.x?alertId=18883http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8118.shtmlhttp://www.securityfocus.com/bid/36496http://www.securitytracker.com/id?1022931http://www.vupen.com/english/advisories/2009/2757https://exchange.xforce.ibmcloud.com/vulnerabilities/53447http://osvdb.org/58344http://secunia.com/advisories/36836http://tools.cisco.com/security/center/viewAlert.x?alertId=18883http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8118.shtmlhttp://www.securityfocus.com/bid/36496http://www.securitytracker.com/id?1022931http://www.vupen.com/english/advisories/2009/2757https://exchange.xforce.ibmcloud.com/vulnerabilities/53447
2009-09-28
Published