CVE-2010-0590
published 2010-03-05CVE-2010-0590: The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.51%
83.0th percentile
The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug ID CSCtc37188.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hq4-73p9-hvch: The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7
ghsa_unreviewed·2022-05-02
CVE-2010-0590 [HIGH] GHSA-4hq4-73p9-hvch: The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7
The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug ID CSCtc37188.
Cisco
Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
vendor_cisco·2010-03-03·CVSS 7.8
CVE-2010-0587 [HIGH] CWE-399 Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
A vulnerability exists in the Cisco Digital Media Player that could
allow an unauthenticated attacker to inject video or data content into a remote
display.
Cisco has released software updates that address this vulnerability. There are no workarounds available to mitigate this
vulnerability.
This additional advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100303-dmp.
Note: This advisory is being released simultaneously with a multiple
vulnerability disclosure advisory that impacts the Cisco Digital Media Manager.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100303-dmm.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2010-0590 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2010-0590: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly Cisco CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption of voice services. The Session Initiation Protocol (SIP), Skinny Client Control Protocol (SCCP) and Computer Telephony Integration (CTI) Manager services are affected by these vulnerabilities. To address these vulnerabilities, Cisco has released free software updates for select Cisco Unified Communications Manager versions. There is a workaround for of one the vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100303-cucm .
Bug IDs: CSCtc38985, CSCtc47823, C
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1023670http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtmlhttp://www.securityfocus.com/bid/38495http://securitytracker.com/id?1023670http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtmlhttp://www.securityfocus.com/bid/38495
2010-03-05
Published