CVE-2008-1747: Input Validation
Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (CCM service restart) via an unspecified SIP INVITE message, aka Bug ID CSCsk46944.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1747?
CVE-2008-1747 has been classified as a denial of service vulnerability affecting certain versions of Cisco Unified Communications Manager.
How do I fix CVE-2008-1747?
To address CVE-2008-1747, upgrade the Cisco Unified Communications Manager to a version that is not vulnerable, specifically to 4.1(3)SR6, 4.2(3)SR3, 4.3(2), 5.1(3), or 6.1(1) or newer.
What products are affected by CVE-2008-1747?
CVE-2008-1747 affects Cisco Unified Communications Manager versions prior to 4.1(3)SR6, 4.2(3)SR3, 4.3(2), 5.1(3), and 6.1(1).
What types of attacks can exploit CVE-2008-1747?
CVE-2008-1747 can be exploited by remote attackers sending specially crafted SIP INVITE messages to cause a denial of service.
Is there a workaround for CVE-2008-1747?
There are no specific workarounds for CVE-2008-1747; the best mitigation is to upgrade to a patched version of the software.