Description
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.
References (6)
Core 6
Core References
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36499
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36152
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36498
Broken Link, Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtml
Broken Link vdb-entry
x_refsource_osvdb
http://osvdb.org/57456
Broken Link, Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1022775
Scores
EPSS
0.0340
EPSS Percentile
87.3%
Details
CWE
CWE-770
Status
published
Products (1)
cisco/unified_communications_manager
4.0 - 5.1\(3g\)
Published
Aug 27, 2009
Tracked Since
Feb 18, 2026