CVE-2013-3461
Cisco Unified Communications Manager 8.5(x)-8.6(x) and 9.x - Denial of Service via SIP Packet Flood
Title source: llmDescription
Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service disruption) via a flood of UDP packets to port 5060, aka Bug ID CSCub35869.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130821-cucm
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1028938
Scores
EPSS
0.0135
EPSS Percentile
68.5%
Details
CWE
CWE-399
Status
published
Products (15)
cisco/unified_communications_manager
9.0\(1\)
cisco/unified_communications_manager
8.5
cisco/unified_communications_manager
8.5\(1\)
cisco/unified_communications_manager
8.5\(1\)su1
cisco/unified_communications_manager
8.5\(1\)su2
cisco/unified_communications_manager
8.5\(1\)su3
cisco/unified_communications_manager
8.5\(1\)su4
cisco/unified_communications_manager
8.5\(1\)su5
cisco/unified_communications_manager
8.6
cisco/unified_communications_manager
8.6\(1\)
... and 5 more
Published
Aug 25, 2013
Tracked Since
Feb 18, 2026