CVE-2009-0057: Input Validation
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0057?
CVE-2009-0057 has been rated as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2009-0057?
To fix CVE-2009-0057, upgrade your Cisco Unified Communications Manager to version 5.1(3e) or later if you are running 5.x, or to version 6.1(3) or later if you are running 6.x.
What systems are affected by CVE-2009-0057?
CVE-2009-0057 affects Cisco Unified Communications Manager versions 5.x and 6.x prior to the specified patches.
What kind of attacks can exploit CVE-2009-0057?
CVE-2009-0057 can be exploited by sending malformed input over a TCP session, leading to a voice service outage.
Is there a workaround for CVE-2009-0057?
There is no official workaround for CVE-2009-0057; users are advised to apply the software updates to mitigate the risk.