Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service disruption) via a flood of UDP packets to port 5060, aka Bug ID CSCub35869.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130821-cucm | Vendor Advisory |
http://www.securitytracker.com/id/1028938 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2013-08-24 20:27
Updated : 2016-11-07 06:47
NVD link : CVE-2013-3461
Mitre link : CVE-2013-3461
JSON object : View
CWE
CWE-399
Resource Management Errors
Products Affected
cisco
- unified_communications_manager