CVE-2012-3949
published 2012-09-27CVE-2012-3949: The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.20%
86.8th percentile
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.
Affected
261 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2012-09-26·CVSS 7.8
CVE-2012-3949 [HIGH] Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
Cisco Unified Communications Manager contains a vulnerability in its Session Initiation Protocol (SIP) implementation that could allow an unauthenticated, remote attacker to cause a critical service to fail, which could interrupt voice services. Affected devices must be configured to process SIP messages for this vulnerability to be exploitable.
Cisco has released software updates that address this vulnerability. A workaround exists for customers who do not require SIP in their environment.
This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-cucm.
Note: The September 26, 2012, Cisco IOS Software Security Advisory bund
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco·2012-09-26·CVSS 7.8
CVE-2012-3949 [HIGH] CWE-399 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
A vulnerability exists in the Session Initiation Protocol (SIP) implementation in Cisco IOS Software and Cisco IOS XE Software that could allow an unauthenticated, remote attacker to cause an affected device to reload. Affected devices must be configured to process SIP messages and for pass-through of Session Description Protocol (SDP) for this vulnerability to be exploitable.
Cisco has released software updates that address this vulnerability. There are no workarounds for devices that must run SIP; however, mitigations are available to limit exposure to the vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-
Cisco
Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
vendor_cisco
CVE-2012-3949 Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
CVE-2012-3949: Cisco Unified Communications Manager Session Initiation Protocol Denial of Service Vulnerability
Cisco Unified Communications Manager contains a vulnerability in its Session Initiation Protocol (SIP) implementation that could allow an unauthenticated, remote attacker to cause a critical service to fail, which could interrupt voice services. Affected devices must be configured to process SIP messages for this vulnerability to be exploitable. Cisco has released software updates that address this vulnerability. A workaround exists for customers who do not require SIP in their environment. This advisory is available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-cucm . Note: The September 26, 2012, Cisco IOS Software Security A
GHSA
GHSA-g9vp-vrrf-jgjx: The SIP implementation in Cisco Unified Communications Manager (CUCM) 6
ghsa_unreviewed·2022-05-17
CVE-2012-3949 [HIGH] CWE-20 GHSA-g9vp-vrrf-jgjx: The SIP implementation in Cisco Unified Communications Manager (CUCM) 6
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/85816http://secunia.com/advisories/50774http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-cucmhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-siphttp://www.securityfocus.com/bid/55697http://osvdb.org/85816http://secunia.com/advisories/50774http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-cucmhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120926-siphttp://www.securityfocus.com/bid/55697
2012-09-27
Published