First published: Thu Oct 18 2007(Updated: )
Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | =5.0 | |
Cisco Unified Communications Manager | <=5.1\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5537 has a high severity rating due to its potential to cause a denial of service by triggering a kernel panic.
To mitigate CVE-2007-5537, you should upgrade your Cisco Unified Communications Manager to version 5.1(2) or later.
CVE-2007-5537 affects users of Cisco Unified Communications Manager versions 5.0 and below 5.1(2).
An attacker can exploit CVE-2007-5537 by flooding the server with SIP INVITE messages, leading to denial of service.
Currently, there are no official workarounds for CVE-2007-5537 other than applying the recommended patch or upgrade.