CVE-2009-2052: High severity Cisco Unified Communications Manager vulnerability
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "tracking of network connections," aka Bug IDs CSCsq22534 and CSCsw52371.
Affected Software
Remediation
Event History
Frequently Asked Questions
What versions of Cisco Unified Communications Manager are affected by CVE-2009-2052?
CVE-2009-2052 affects Cisco Unified Communications Manager versions 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2).
What is the impact of CVE-2009-2052?
CVE-2009-2052 can lead to a denial of service, allowing remote attackers to disrupt TCP services of the affected systems.
How can I mitigate CVE-2009-2052?
Mitigation for CVE-2009-2052 involves updating the Cisco Unified Communications Manager to a version that is not affected, such as version 5.1(3g) or later.
What is the recommended action for users of affected Cisco products regarding CVE-2009-2052?
Users should immediately upgrade to the fixed versions of Cisco Unified Communications Manager to prevent potential denial of service attacks.
Is there a patch available for CVE-2009-2052?
Yes, patches and updates that address CVE-2009-2052 are available from Cisco for the affected versions.