CVE-2010-1570
published 2010-06-10CVE-2010-1570: The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.52%
83.2th percentile
The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | customer_response_solution | — | — |
| cisco | customer_response_solution | — | — |
| cisco | customer_response_solution | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_ip_interactive_voice_response | — | — |
| cisco | unified_ip_interactive_voice_response | — | — |
| cisco | unified_ip_interactive_voice_response | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjjr-c6mv-9759: The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7
ghsa_unreviewed·2022-05-17
CVE-2010-1570 [HIGH] GHSA-cjjr-c6mv-9759: The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7
The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message.
Cisco
Vulnerabilities in Cisco Unified Contact Center Express
vendor_cisco
CVE-2010-1570 Vulnerabilities in Cisco Unified Contact Center Express
CVE-2010-1570: Vulnerabilities in Cisco Unified Contact Center Express
Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. These vulnerabilities are independent of each other. Exploitation of these vulnerabilities could result in a DoS condition or an information disclosure. Cisco has released software updates that address these vulnerabilities in the latest versions of Cisco Unified Contact Center products. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100609-uccx .
CWE: CWE-22, CWE-399, CWE-22, CWE-399
Bug IDs: CSCso89629, CSCsx76165, CSCso89629, CSCsx76165
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2f110.shtmlhttp://www.securityfocus.com/bid/40684http://www.securitytracker.com/id?1024081https://exchange.xforce.ibmcloud.com/vulnerabilities/59276http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2f110.shtmlhttp://www.securityfocus.com/bid/40684http://www.securitytracker.com/id?1024081https://exchange.xforce.ibmcloud.com/vulnerabilities/59276
2010-06-10
Published