First published: Fri May 16 2008(Updated: )
Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (CCM service restart) via an unspecified SIP INVITE message, aka Bug ID CSCsk46944.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | >=4.1<4.1\(3\)sr6 | |
Cisco Unified Communications Manager | >=4.2<4.2\(3\)sr3 | |
Cisco Unified Communications Manager | >=4.3<4.3\(2\) | |
Cisco Unified Communications Manager | >=5.0<5.1\(3\) | |
Cisco Unified Communications Manager | >=6.0<6.1\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1747 has been classified as a denial of service vulnerability affecting certain versions of Cisco Unified Communications Manager.
To address CVE-2008-1747, upgrade the Cisco Unified Communications Manager to a version that is not vulnerable, specifically to 4.1(3)SR6, 4.2(3)SR3, 4.3(2), 5.1(3), or 6.1(1) or newer.
CVE-2008-1747 affects Cisco Unified Communications Manager versions prior to 4.1(3)SR6, 4.2(3)SR3, 4.3(2), 5.1(3), and 6.1(1).
CVE-2008-1747 can be exploited by remote attackers sending specially crafted SIP INVITE messages to cause a denial of service.
There are no specific workarounds for CVE-2008-1747; the best mitigation is to upgrade to a patched version of the software.