CVE-2009-2864: High severity cisco unified communications solutions vulnerability
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2864?
CVE-2009-2864 has a high severity rating due to its potential to cause a denial of service through malformed SIP messages.
How do I fix CVE-2009-2864?
To fix CVE-2009-2864, upgrade to the patched versions of Cisco Unified Communications Manager specified in the security advisory.
What versions of Cisco Unified Communications Manager are affected by CVE-2009-2864?
CVE-2009-2864 affects Cisco Unified Communications Manager versions 5.x prior to 5.1(3g), 6.x prior to 6.1(4), and 7.0.x prior to 7.0(2a)su1.
How can CVE-2009-2864 be exploited?
CVE-2009-2864 can be exploited by remote attackers sending specially crafted SIP messages to the affected Cisco devices.
Is there a known patch for CVE-2009-2864?
Yes, Cisco provides specific patches for CVE-2009-2864 within the advised versions of their Unified Communications Manager software.