First published: Thu Aug 27 2009(Updated: )
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "tracking of network connections," aka Bug IDs CSCsq22534 and CSCsw52371.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | >=6.1\(1\)<6.1\(4\) | |
Cisco Unified Communications Manager | >=5.0<5.1\(3g\) | |
Cisco Unified Communications Manager | >=7.1<7.1\(2\) | |
Cisco Unified Communications Manager | >=7.0<7.0\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2052 affects Cisco Unified Communications Manager versions 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2).
CVE-2009-2052 can lead to a denial of service, allowing remote attackers to disrupt TCP services of the affected systems.
Mitigation for CVE-2009-2052 involves updating the Cisco Unified Communications Manager to a version that is not affected, such as version 5.1(3g) or later.
Users should immediately upgrade to the fixed versions of Cisco Unified Communications Manager to prevent potential denial of service attacks.
Yes, patches and updates that address CVE-2009-2052 are available from Cisco for the affected versions.