CVE-2010-2840Improper Input Validation in Cisco Unified Presence Server

Severity
7.8HIGHNVD
EPSS
0.4%
top 37.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateMay 17

Description

The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

NVDcisco/unified_presence_server22 versions+21

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8q52-6xmp-rvx5: The Presence Engine (PE) service in Cisco Unified Presence 62022-05-17
CVEList
CVE-2010-2840: The Presence Engine (PE) service in Cisco Unified Presence 62010-08-26

📋Vendor Advisories

1
Cisco
Cisco Unified Presence Denial of Service Vulnerabilities2010-08-25
CVE-2010-2840 — Improper Input Validation in Cisco | cvebase