Description
The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/40684
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1024081
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b2f110.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/59276
Scores
EPSS
0.0252
EPSS Percentile
83.2%
Details
Status
published
Products (9)
cisco/customer_response_solution
5.0
cisco/customer_response_solution
6.0
cisco/customer_response_solution
7.0
cisco/unified_contact_center_express
5.0
cisco/unified_contact_center_express
6.0
cisco/unified_contact_center_express
7.0
cisco/unified_ip_interactive_voice_response
5.0
cisco/unified_ip_interactive_voice_response
6.0
cisco/unified_ip_interactive_voice_response
7.0
Published
Jun 10, 2010
Tracked Since
Feb 18, 2026