CVE-2010-0586: High severity Cisco IOS vulnerability
Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug ID CSCsz49741, the "SCCP Request Handling Denial of Service Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0586?
CVE-2010-0586 has a severity rating classified as high, primarily due to its potential to cause a denial of service.
What versions of Cisco IOS are affected by CVE-2010-0586?
CVE-2010-0586 affects Cisco IOS versions 12.1 through 12.4, particularly when CME or SRST is enabled.
How do I fix CVE-2010-0586?
To fix CVE-2010-0586, it is recommended to upgrade to a Cisco IOS version that is not affected, as per Cisco's security advisory.
What is the impact of CVE-2010-0586 on Cisco devices?
The impact of CVE-2010-0586 allows remote attackers to send malformed SCCP messages that can trigger a device reload, resulting in denial of service.
Does CVE-2010-0586 require authentication to exploit?
CVE-2010-0586 can be exploited remotely without authentication, making it a significant security risk.