CVE-2010-0587: High severity Cisco Unified Communications Manager vulnerability
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0587?
CVE-2010-0587 is classified as a denial of service vulnerability that can lead to process failures.
How do I fix CVE-2010-0587?
To mitigate CVE-2010-0587, upgrade your Cisco Unified Communications Manager to a version that is not affected, such as 4.3(2)SR2 or later.
Which versions of Cisco Unified Communications Manager are affected by CVE-2010-0587?
CVE-2010-0587 affects Cisco Unified Communications Manager versions 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1).
What type of attack does CVE-2010-0587 facilitate?
CVE-2010-0587 allows remote attackers to exploit the vulnerability through malformed SCCP StationCapabilitiesRes messages.
Can CVE-2010-0587 lead to data loss?
While CVE-2010-0587 primarily causes a denial of service, indirect effects such as lost calls or service interruptions may occur.