CVE-2010-4686

Cisco IOS < 15.0(1)XA1 - Denial of Service via SIP TRUNK Traffic

Title source: llm
STIX 2.1

Description

CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" request size, which allows remote attackers to cause a denial of service (memory consumption) by sending this traffic over a long duration, aka Bug ID CSCtb47950.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64585
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45769

Scores

EPSS 0.0318
EPSS Percentile 86.4%

Details

CWE
CWE-400
Status published
Products (1)
cisco/ios < 15.0\(1\)xa1
Published Jan 07, 2011
Tracked Since Feb 18, 2026