CVE-2012-0367
published 2012-03-01CVE-2012-0367: Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.64%
83.9th percentile
Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unity_connection | <= 7.1\(5b\)su4 | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
| cisco | unity_connection | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5rm-73fv-w3f7: Cisco Unity Connection before 7
ghsa_unreviewed·2022-05-04
CVE-2012-0367 [HIGH] GHSA-f5rm-73fv-w3f7: Cisco Unity Connection before 7
Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899.
Cisco
Multiple Vulnerabilities in Cisco Unity Connection
vendor_cisco·2012-03-01·CVSS 9.0
CVE-2012-0366 [CRITICAL] Multiple Vulnerabilities in Cisco Unity Connection
Multiple Vulnerabilities in Cisco Unity Connection
Cisco Unity Connection contains two vulnerabilities:
Cisco Unity Connection Privilege Escalation Vulnerability
Cisco Unity Connection Denial of Service Vulnerability
Exploitation of the Cisco Unity Connection Privilege Escalation Vulnerability may allow an authenticated, remote attacker to elevate privileges and obtain full access to the affected system.
Exploitation of the Cisco Unity Connection Denial of Service Vulnerability may allow an unauthenticated, remote attacker to cause system services to terminate unexpectedly, which may result in a denial of service condition.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities.
This advisory is available at
Cisco
Multiple Vulnerabilities in Cisco Unity Connection
vendor_cisco
CVE-2012-0367 Multiple Vulnerabilities in Cisco Unity Connection
CVE-2012-0367: Multiple Vulnerabilities in Cisco Unity Connection
Cisco Unity Connection contains two vulnerabilities: Cisco Unity Connection Privilege Escalation Vulnerability Cisco Unity Connection Denial of Service Vulnerability Exploitation of the Cisco Unity Connection Privilege Escalation Vulnerability may allow an authenticated, remote attacker to elevate privileges and obtain full access to the affected system. Exploitation of the Cisco Unity Connection Denial of Service Vulnerability may allow an unauthenticated, remote attacker to cause system services to terminate unexpectedly, which may result in a denial of service condition. Cisco has released software updates that address these vulnerabilities. There are no
Bug IDs: CSCtd45141, CSCtq67899, CSCtd45141, CSCtq67899, CSCtd45141
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-03-01
Published