CVE-2009-2874: High severity cisco unified presence vulnerability
Published Oct 16, 2009
·Updated
The TimesTenD process in Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4) allows remote attackers to cause a denial of service (process crash) via a large number of TCP connections to ports 16200 and 22794, aka Bug ID CSCsy17662.
Affected Software
12 affected components
Cisco Unified Presence Server=1.0
Cisco Unified Presence Server=7.0\(2\)
Cisco Unified Presence Server=6.0
Cisco Unified Presence Server=1.0\(1\)
Cisco Unified Presence Server=6.0\(3\)
Cisco Unified Presence Server=1.0\(3\)
Cisco Unified Presence Server=6.0\(2\)
Cisco Unified Presence Server=7.0\(3\)
Cisco Unified Presence Server=7.0
Cisco Unified Presence Server=6.0\(4\)
Cisco Unified Presence Server=1.0\(2\)
Cisco Unified Presence Server=6.0\(5\)
Remediation
Event History
Oct 16, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2874?
CVE-2009-2874 is classified as a denial of service vulnerability.
2
How do I fix CVE-2009-2874?
To fix CVE-2009-2874, upgrade the Cisco Unified Presence Server to versions 6.0(6) or 7.0(4) or later.
3
What products are affected by CVE-2009-2874?
CVE-2009-2874 affects Cisco Unified Presence Server versions 1.x, 6.x before 6.0(6), and 7.x before 7.0(4).
4
What type of attack vector is associated with CVE-2009-2874?
CVE-2009-2874 can be exploited through a large number of TCP connections to specific ports.
5
What impact can CVE-2009-2874 have on my systems?
Exploitation of CVE-2009-2874 can lead to a denial of service, causing the process to crash.