First published: Thu Aug 27 2009(Updated: )
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2) allows remote attackers to cause a denial of service (file-descriptor exhaustion and SCCP outage) via a flood of TCP packets, aka Bug ID CSCsx32236.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager Session Management Edition | >=6.1\(1\)<6.1\(4\) | |
Cisco Unified Communications Manager Session Management Edition | >=5.0<5.1\(3g\) | |
Cisco Unified Communications Manager Session Management Edition | >=7.1<7.1\(2\) | |
Cisco Unified Communications Manager Session Management Edition | >=7.0<7.0\(2a\)su1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2053 is categorized as a denial of service vulnerability affecting multiple versions of Cisco Unified Communications Manager.
To mitigate CVE-2009-2053, you should update Cisco Unified Communications Manager to versions 5.1(3g), 6.1(4), 7.0(2a)su1 or 7.1(2) or later.
CVE-2009-2053 affects Cisco Unified Communications Manager versions 4.x, 5.x, 6.x, and 7.x prior to their respective fixed versions.
CVE-2009-2053 can be exploited through a flood of TCP packets that leads to file-descriptor exhaustion and an SCCP outage.
The denial of service vulnerability CVE-2009-2053 requires remote access and is primarily dependent on the ability to send a high volume of TCP packets.