Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
BID:29221
Info
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 29221 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1744 CVE-2008-1745 CVE-2008-1746 CVE-2008-1747 CVE-2008-1748 CVE-2008-1749 CVE-2008-1742 CVE-2008-1743 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2008 12:00AM |
| Updated: | May 14 2008 11:35PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Cisco Unified Communications Manager 6.1(1a) Cisco Unified Communications Manager 6.1 Cisco Unified Communications Manager 6.0(1) Cisco Unified Communications Manager 6.0 (1a) Cisco Unified Communications Manager 6.0 Cisco Unified Communications Manager 5.1(3a) Cisco Unified Communications Manager 5.1(2b) Cisco Unified Communications Manager 5.1(2a) Cisco Unified Communications Manager 5.1(2) Cisco Unified Communications Manager 5.1(1) Cisco Unified Communications Manager 4.3(1)Sr.1 Cisco Unified Communications Manager 4.3 Cisco Unified Communications Manager 4.2(3)sr2 Cisco Unified Communications Manager 4.2 (3)SR3 Cisco Unified Communications Manager 4.2 (3)SR2b Cisco Unified CallManager 4.1(3)sr5 Cisco Unified CallManager 4.1(3)sr5 Cisco Unified CallManager 4.1(3)SR4 Cisco Unified CallManager 4.1 (3)SR5c Cisco Unified CallManager 4.1 (3)SR5b Cisco Unified CallManager 4.1 |
| Not Vulnerable: |
Cisco Unified Communications Manager 6.1(1) Cisco Unified Communications Manager 5.1(3) Cisco Unified Communications Manager 4.3(2) Cisco Unified Communications Manager 4.2 (3)SR4 Cisco Unified CallManager 4.1(3)SR7 |
Discussion
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
Cisco Unified Communications Manager is prone to multiple denial-of-service vulnerabilities.
These issues affect the following components:
Certificate Trust List (CTL) Provider
Certificate Authority Proxy Function (CAPF)
Session Initiation Protocol (SIP)
Simple Network Management Protocol (SNMP) Trap
An attacker can exploit these issues to cause denial-of-service conditions in the affected application.
Cisco Unified Communications Manager is prone to multiple denial-of-service vulnerabilities.
These issues affect the following components:
Certificate Trust List (CTL) Provider
Certificate Authority Proxy Function (CAPF)
Session Initiation Protocol (SIP)
Simple Network Management Protocol (SNMP) Trap
An attacker can exploit these issues to cause denial-of-service conditions in the affected application.
Exploit / POC
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
To exploit these issues, attackers can use readily available network utilities.
To exploit these issues, attackers can use readily available network utilities.
Solution / Fix
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
Solution:
The vendor has released updates. Please see the referenced advisory for more information.
References
Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
References:
References:
- Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Cisc (Cisco)
- Cisco Homepage (Cisco )
- Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service (Cisco Systems Product Security Incident Response Team
) - Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service (Cisco)