Vulnerability Name: CVE-2009-2051 (CCN-52814) Assigned: 2009-08-26 Published: 2009-08-26 Updated: 2021-10-06 Summary: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987. CVSS v3 Severity: 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
CVSS v2 Severity: 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
Vulnerability Type: CWE-Other Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2009-2051 Source: OSVDB Type: Broken Link57453 Source: CCN Type: SA36495Cisco Unified Communications Manager SIP Header Denial of Service Source: CCN Type: SA36498Cisco Unified Communications Manager Denial of Service Vulnerabilities Source: SECUNIA Type: Third Party Advisory36498 Source: CCN Type: SA36499Cisco Unified Communications Manager Denial of Service Vulnerabilities Source: SECUNIA Type: Third Party Advisory36499 Source: CCN Type: SECTRACK ID: 1022775Cisco Unified Communications Manager SIP and SCCP Processing Bugs Let Remote Users Deny Service Source: CCN Type: Cisco Applied Mitigation Bulletin: Document ID: 110849Identifying and Mitigating Exploitation of the Cisco Unified Communications Manager Denial of Service Vulnerabilities Source: CISCO Type: Patch, Vendor Advisory20090826 Cisco Unified Communications Manager Denial of Service Vulnerabilities Source: CCN Type: cisco-sa-20100922-sipCisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities Source: CISCO Type: Vendor Advisory20100922 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities Source: CCN Type: cisco-sa-20090826-cucmCisco Unified Communications Manager Denial of Service Vulnerabilities Source: CCN Type: OSVDB ID: 57453Cisco Unified Communications Manager SIP Trunk Malformed Packet Handling Remote DoS Source: BID Type: Third Party Advisory, VDB Entry36152 Source: CCN Type: BID-36152Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities Source: SECTRACK Type: Third Party Advisory, VDB Entry1022775 Source: XF Type: UNKNOWNcucm-sip-invite-message-dos(52814) Vulnerable Configuration: Configuration 1 :cpe:/a:cisco:unified_communications_manager:*:*:*:*:*:*:*:* (Version >= 5.0 and < 5.1(3g))OR cpe:/a:cisco:unified_communications_manager:*:*:*:*:*:*:*:* (Version >= 6.1(1) and < 6.1(4)) OR cpe:/a:cisco:unified_communications_manager:*:*:*:*:*:*:*:* (Version >= 7.1 and < 7.1(2)) OR cpe:/o:cisco:ios:*:*:*:*:*:*:*:* (Version >= 12.2 and <= 12.4) OR cpe:/o:cisco:ios:*:*:*:*:*:*:*:* (Version >= 15.0 and <= 15.1) OR cpe:/o:cisco:ios_xe:*:*:*:*:*:*:*:* (Version >= 2.5.0 and <= 2.6.1) Configuration CCN 1 :cpe:/a:cisco:unified_communications_manager:5.1(2b):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.0(1a):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:3.3(5):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1(3):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2.2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2.3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2.3sr1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2.3sr2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2.3sr2b:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1(2):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.0:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1(1a):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:3.3(5)sr1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:3.3(5)sr2a:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1(3)sr1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1(3)sr2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1(3)sr3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1(3)sr4:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.0(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1(2)su1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1(2):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1(2a):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1(3d):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1(3):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1(3a):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1(3c):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:7.0:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1(3):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3(1)sr.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3(2):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3(2)sr1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1.2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.1.3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:(2):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:(2b):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:::business:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2(3)sr3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2(3)sr2b:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2(3)sr1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2(3)sr4:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2_2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2_3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2.3_sr3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2_1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2_3_sr3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2_3_sr2b:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2_3sr1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0_1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0_2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3_1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3.2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0_4:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0_3a:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0_3:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.2_3_sr2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:4.3_1_sr1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1:(2a):*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1.2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0_4a:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.0_4a_su1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.0_1a:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.0_1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1_3a:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1_2b:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1_2a:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1_2:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:5.1_1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:7.0(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_communications_manager:6.1_1a:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
cisco unified communications manager *
cisco unified communications manager *
cisco unified communications manager *
cisco ios *
cisco ios *
cisco ios xe *
cisco unified communications manager 5.1(2b)
cisco unified communications manager 6.0(1a)
cisco unified communications manager 5.0
cisco unified communications manager 3.3(5)
cisco unified communications manager 4.1(3)
cisco unified communications manager 4.2
cisco unified communications manager 4.2.1
cisco unified communications manager 4.2.2
cisco unified communications manager 4.2.3
cisco unified communications manager 4.2.3sr1
cisco unified communications manager 4.2.3sr2
cisco unified communications manager 4.2.3sr2b
cisco unified communications manager 4.3
cisco unified communications manager 4.3(1)
cisco unified communications manager 5.1
cisco unified communications manager 5.1(1)
cisco unified communications manager 5.1(2)
cisco unified communications manager 6.0
cisco unified communications manager 6.1(1a)
cisco unified communications manager 4.1
cisco unified communications manager 6.1
cisco unified communications manager 6.1(1)
cisco unified communications manager 3.3(5)sr1
cisco unified communications manager 3.3(5)sr2a
cisco unified communications manager 4.1(3)sr1
cisco unified communications manager 4.1(3)sr2
cisco unified communications manager 4.1(3)sr3
cisco unified communications manager 4.1(3)sr4
cisco unified communications manager 6.0(1)
cisco unified communications manager 6.1(2)su1
cisco unified communications manager 6.1(2)
cisco unified communications manager 5.1(2a)
cisco unified communications manager 5.1(3d)
cisco unified communications manager 5.1(3)
cisco unified communications manager 5.1(3a)
cisco unified communications manager 5.1(3c)
cisco unified communications manager 7.0
cisco unified communications manager 6.1(3)
cisco unified communications manager 4.3(1)sr.1
cisco unified communications manager 4.3(2)
cisco unified communications manager 4.3(2)sr1
cisco unified communications manager 4.1.1
cisco unified communications manager 4.1.2
cisco unified communications manager 4.1.3
cisco unified communications manager (2)
cisco unified communications manager (1)
cisco unified communications manager (2b)
cisco unified communications manager
cisco unified communications manager 4.2(3)sr3
cisco unified communications manager 4.2(3)sr2b
cisco unified communications manager 4.2(3)sr1
cisco unified communications manager 4.2(3)sr4
cisco unified communications manager 4.2_2
cisco unified communications manager 4.2_3
cisco unified communications manager 4.2.3_sr3
cisco unified communications manager 4.2_1
cisco unified communications manager 4.2_3_sr3
cisco unified communications manager 4.2_3_sr2b
cisco unified communications manager 4.2_3sr1
cisco unified communications manager 5.0_1
cisco unified communications manager 5.0_2
cisco unified communications manager 4.3_1
cisco unified communications manager 4.3.1
cisco unified communications manager 4.3.2
cisco unified communications manager 5.0_4
cisco unified communications manager 5.0_3a
cisco unified communications manager 5.0_3
cisco unified communications manager 4.2_3_sr2
cisco unified communications manager 4.3_1_sr1
cisco unified communications manager 5.1 (2a)
cisco unified communications manager 5.1.2
cisco unified communications manager 5.0_4a
cisco unified communications manager 5.0_4a_su1
cisco unified communications manager 6.0_1a
cisco unified communications manager 6.0_1
cisco unified communications manager 5.1_3a
cisco unified communications manager 5.1_2b
cisco unified communications manager 5.1_2a
cisco unified communications manager 5.1_2
cisco unified communications manager 5.1_1
cisco unified communications manager 6.1.0
cisco unified communications manager 7.0(1)
cisco unified communications manager 6.1_1a