Vulnerability Name: | CVE-2015-0613 (CCN-101989) | ||||||||
Assigned: | 2015-04-01 | ||||||||
Published: | 2015-04-01 | ||||||||
Updated: | 2015-09-29 | ||||||||
Summary: | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul20444. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-19 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-0613 Source: CCN Type: Cisco Security Advisory ID: cisco-sa-20150401-cuc Multiple Vulnerabilities in Cisco Unity Connection Source: CISCO Type: Vendor Advisory 20150401 Multiple Vulnerabilities in Cisco Unity Connection Source: SECTRACK Type: UNKNOWN 1032010 Source: XF Type: UNKNOWN cisco-unity-cve20150613-dos(101989) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |