CVE-2010-0591: High severity Cisco Unified Communications Manager vulnerability
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0591?
CVE-2010-0591 is classified as a denial of service vulnerability.
How do I fix CVE-2010-0591?
To fix CVE-2010-0591, upgrade to a version of Cisco Unified Communications Manager that is not affected, such as 6.1(5) or later.
Which versions of Cisco Unified Communications Manager are affected by CVE-2010-0591?
CVE-2010-0591 affects Cisco Unified Communications Manager versions 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1).
What is the impact of CVE-2010-0591?
The impact of CVE-2010-0591 is that it allows remote attackers to cause a denial of service via a malformed SIP REG message.
Is CVE-2010-0591 exploitable remotely?
Yes, CVE-2010-0591 is exploitable remotely, allowing attackers to trigger process failures.