CVE-2013-1134
published 2013-02-27CVE-2013-1134: The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require…
PriorityP431high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.29%
67.1th percentile
The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the remote LBM Hub node, which allows remote attackers to conduct cache-poisoning attacks against transaction records, and cause a denial of service (bandwidth-pool consumption and call outage), via unspecified vectors, aka Bug ID CSCub28920.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager_multiple | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
vendor_cisco·2013-02-27·CVSS 7.8
CVE-2013-1133 [HIGH] CWE-20 Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
Cisco Unified Communications Manager contains two vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. Exploitation of these vulnerabilities could cause an interruption of voice services.
Cisco has released software updates that address these vulnerabilities. This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130227-cucm
Cisco
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
vendor_cisco
CVE-2013-1134 Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
CVE-2013-1134: Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
Cisco Unified Communications Manager contains two vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. Exploitation of these vulnerabilities could cause an interruption of voice services. Cisco has released software updates that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130227-cucm
CWE: CWE-20, CWE-264, CWE-20, CWE-264
Bug IDs: CSCtx43337, CSCub28920, CSCtx43337, CSCub28920
GHSA
GHSA-92m6-46vg-vqrh: The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9
ghsa_unreviewed·2022-05-17
CVE-2013-1134 [HIGH] CWE-287 GHSA-92m6-46vg-vqrh: The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9
The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the remote LBM Hub node, which allows remote attackers to conduct cache-poisoning attacks against transaction records, and cause a denial of service (bandwidth-pool consumption and call outage), via unspecified vectors, aka Bug ID CSCub28920.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-02-27
Published