First published: Thu Mar 25 2010(Updated: )
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Puppet Cisco IOS | =12.3jk | |
Puppet Cisco IOS | =12.3t | |
Puppet Cisco IOS | =12.3xd | |
Puppet Cisco IOS | =12.3xf | |
Puppet Cisco IOS | =12.3xg | |
Puppet Cisco IOS | =12.3xi | |
Puppet Cisco IOS | =12.3xj | |
Puppet Cisco IOS | =12.3xk | |
Puppet Cisco IOS | =12.3xl | |
Puppet Cisco IOS | =12.3xq | |
Puppet Cisco IOS | =12.3xr | |
Puppet Cisco IOS | =12.3xu | |
Puppet Cisco IOS | =12.3xw | |
Puppet Cisco IOS | =12.3xx | |
Puppet Cisco IOS | =12.3xy | |
Puppet Cisco IOS | =12.3xz | |
Puppet Cisco IOS | =12.3yf | |
Puppet Cisco IOS | =12.3yg | |
Puppet Cisco IOS | =12.3yk | |
Puppet Cisco IOS | =12.3ym | |
Puppet Cisco IOS | =12.3yq | |
Puppet Cisco IOS | =12.3ys | |
Puppet Cisco IOS | =12.3yt | |
Puppet Cisco IOS | =12.3yu | |
Puppet Cisco IOS | =12.3yx | |
Puppet Cisco IOS | =12.3yz | |
Puppet Cisco IOS | =12.3za | |
Puppet Cisco IOS | =12.4 | |
Puppet Cisco IOS | =12.4gc | |
Puppet Cisco IOS | =12.4md | |
Puppet Cisco IOS | =12.4mda | |
Puppet Cisco IOS | =12.4mr | |
Puppet Cisco IOS | =12.4t | |
Puppet Cisco IOS | =12.4xa | |
Puppet Cisco IOS | =12.4xb | |
Puppet Cisco IOS | =12.4xd | |
Puppet Cisco IOS | =12.4xp | |
Puppet Cisco IOS | =12.4xr | |
Puppet Cisco IOS | =12.4xt | |
Puppet Cisco IOS | =12.4ya | |
Puppet Cisco IOS | =12.4yb | |
Puppet Cisco IOS | =12.4yd | |
Puppet Cisco IOS | =12.4ye | |
Puppet Cisco IOS | =12.4yg |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0581 has a severity rating that indicates a potential for arbitrary code execution on affected Cisco IOS versions.
To fix CVE-2010-0581, upgrade to a version of Cisco IOS that does not contain this vulnerability, as detailed in Cisco's security advisory.
CVE-2010-0581 affects multiple versions of Cisco IOS, including 12.3 and 12.4 variants.
Yes, CVE-2010-0581 can be exploited remotely via malformed SIP messages.
Exploitation of CVE-2010-0581 could lead to arbitrary code execution, allowing attackers to compromise device security.