CVE-2009-2053: High severity Cisco Unified Communications Manager vulnerability
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2) allows remote attackers to cause a denial of service (file-descriptor exhaustion and SCCP outage) via a flood of TCP packets, aka Bug ID CSCsx32236.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2053?
CVE-2009-2053 is categorized as a denial of service vulnerability affecting multiple versions of Cisco Unified Communications Manager.
How do I fix CVE-2009-2053?
To mitigate CVE-2009-2053, you should update Cisco Unified Communications Manager to versions 5.1(3g), 6.1(4), 7.0(2a)su1 or 7.1(2) or later.
What systems are affected by CVE-2009-2053?
CVE-2009-2053 affects Cisco Unified Communications Manager versions 4.x, 5.x, 6.x, and 7.x prior to their respective fixed versions.
What type of attack exploits CVE-2009-2053?
CVE-2009-2053 can be exploited through a flood of TCP packets that leads to file-descriptor exhaustion and an SCCP outage.
Is CVE-2009-2053 easy to exploit?
The denial of service vulnerability CVE-2009-2053 requires remote access and is primarily dependent on the ability to send a high volume of TCP packets.