CVE-2013-1220
published 2013-05-09CVE-2013-1220: The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.33%
67.7th percentile
The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_customer_voice_portal | <= 9.0\(1\) | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco10.0CRITICAL
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hw: AMD CPU erratum may cause core hang
vendor_redhat·2013-11-28·CVSS 4.7
CVE-2013-6885 [MEDIUM] CWE-1220 hw: AMD CPU erratum may cause core hang
hw: AMD CPU erratum may cause core hang
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
Statement: This hardware issue is affecting certain AMD processors. Please consult your hardware vendor for any potential firmware updates providing a workaround for this issue.
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco·2013-05-08·CVSS 10.0
CVE-2013-1220 [CRITICAL] CWE-119 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "Details" section for more information on the vulnerabilities. These vulnerabilities can be exploited independently; however, more than one vulnerability could be exploited on the same device.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco
CVE-2013-1220 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
CVE-2013-1220: Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "
CWE: CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22, CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22
Bug IDs: CSCua65148, CSCub38366, CSCub38369, CSCua65148, CSCub38366
GHSA
GHSA-jggf-88rj-6q44: The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9
ghsa_unreviewed·2022-05-17
CVE-2013-1220 [HIGH] GHSA-jggf-88rj-6q44: The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9
The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-05-09
Published