CVE-2008-1748: Input Validation
Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1748?
CVE-2008-1748 has a severity rating that indicates it could lead to a denial of service.
How do I fix CVE-2008-1748?
To fix CVE-2008-1748, you should upgrade your Cisco Unified Communications Manager to a version that is not affected by this vulnerability.
What versions of Cisco Unified Communications Manager are affected by CVE-2008-1748?
CVE-2008-1748 affects Cisco Unified Communications Manager versions prior to 4.1(3)SR7, 4.2(3)SR4, 4.3(2), 5.1(3), and 6.1(1).
Can CVE-2008-1748 be exploited remotely?
Yes, CVE-2008-1748 can be exploited remotely via a malicious SIP INVITE message.
What is the impact of CVE-2008-1748?
The impact of CVE-2008-1748 is a denial of service that can interrupt service for users.