CVE-2010-2838Cisco Unified Communications Manager vulnerability

CWE-3994 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.4%
top 37.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateMay 17

Description

The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.0SU before 7.0(2a)SU3, 7.1 before 7.1(5), and 8.0 before 8.0(3) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REGISTER message, aka Bug ID CSCtf66305.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f34g-hcmw-4g52: The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 72022-05-17
CVEList
CVE-2010-2838: The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 72010-08-26

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities2010-08-25
CVE-2010-2838 — Cisco vulnerability | cvebase