First published: Mon Oct 13 2008(Updated: )
Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to cause a denial of service (session exhaustion) via a large number of connections.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unity Server | =5.0 | |
Cisco Unity Server | =4.0 | |
Cisco Unity Server | <=7.0\(2\) | |
Cisco Unity Server | =4.0\(4\)-sr1 | |
Cisco Unity Server | <=4.2\(1\) | |
Cisco Unity Server | =4.0\(3\) | |
Cisco Unity Server | =4.1\(1\) | |
Cisco Unity Server | =4.0\(2\) | |
Cisco Unity Server | =4.0\(5\) | |
Cisco Unity Server | <=5.0\(1\) | |
Cisco Unity Server | =4.0\(4\) | |
Cisco Unity Server | =4.0\(3\)-sr2 | |
Cisco Unity Server | =7.0 | |
Cisco Unity Server | =4.0\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4543 has a severity rating that indicates a medium risk due to the possibility of denial of service through session exhaustion.
To fix CVE-2008-4543, it is recommended to upgrade to the latest version of Cisco Unity that is not affected by this vulnerability.
CVE-2008-4543 affects Cisco Unity versions before 4.2(1)ES161, 5.0(1)ES53, and 7.0(2)ES8.
Yes, CVE-2008-4543 is notably affecting Cisco Unity systems using anonymous authentication.
CVE-2008-4543 enables remote attackers to perform denial of service attacks through session exhaustion.