CVE-2010-0591
published 2010-03-05CVE-2010-0591: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.62%
73.5th percentile
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
vendor_cisco·2010-03-03·CVSS 7.8
CVE-2010-0587 [HIGH] CWE-399 Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
A vulnerability exists in the Cisco Digital Media Player that could
allow an unauthenticated attacker to inject video or data content into a remote
display.
Cisco has released software updates that address this vulnerability. There are no workarounds available to mitigate this
vulnerability.
This additional advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100303-dmp.
Note: This advisory is being released simultaneously with a multiple
vulnerability disclosure advisory that impacts the Cisco Digital Media Manager.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100303-dmm.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2010-0591 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2010-0591: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (formerly Cisco CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption of voice services. The Session Initiation Protocol (SIP), Skinny Client Control Protocol (SCCP) and Computer Telephony Integration (CTI) Manager services are affected by these vulnerabilities. To address these vulnerabilities, Cisco has released free software updates for select Cisco Unified Communications Manager versions. There is a workaround for of one the vulnerabilities. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100303-cucm .
Bug IDs: CSCtc38985, CSCtc47823, C
GHSA
GHSA-p388-jxx8-mrh3: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6
ghsa_unreviewed·2022-05-02
CVE-2010-0591 [HIGH] GHSA-p388-jxx8-mrh3: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1023670http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtmlhttp://www.securityfocus.com/bid/38498http://securitytracker.com/id?1023670http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtmlhttp://www.securityfocus.com/bid/38498
2010-03-05
Published