First published: Fri Mar 05 2010(Updated: )
The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), 7.1x before 7.1(2), and 8.x before 8.0(1) allows remote attackers to cause a denial of service (service failure) via a malformed message, aka Bug ID CSCsu31800.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Communications Manager | =4.2_1 | |
Cisco Unified Communications Manager | =4.1.2 | |
Cisco Unified Communications Manager | =4.1-\(3\)sr5b | |
Cisco Unified Communications Manager | =6.1\(2\) | |
Cisco Unified Communications Manager | =6.1.0 | |
Cisco Unified Communications Manager | =4.2.3sr2 | |
Cisco Unified Communications Manager | =6.0\(1\) | |
Cisco Unified Communications Manager | =4.2_2 | |
Cisco Unified Communications Manager | =4.1.1 | |
Cisco Unified Communications Manager | =4.3_1 | |
Cisco Unified Communications Manager | =4.1\(3\)sr1 | |
Cisco Unified Communications Manager | =6.1\(2\)su1a | |
Cisco Unified Communications Manager | =4.2\(3\)sr2b | |
Cisco Unified Communications Manager | =4.2.3_sr3 | |
Cisco Unified Communications Manager | =6.1-\(1a\) | |
Cisco Unified Communications Manager | =7.1 | |
Cisco Unified Communications Manager | =4.1-\(3\)sr5 | |
Cisco Unified Communications Manager | =4.1-\(3\)sr5c | |
Cisco Unified Communications Manager | =4.2.3sr1 | |
Cisco Unified Communications Manager | =4.1\(3\)sr2 | |
Cisco Unified Communications Manager | =4.3\(2\)sr1 | |
Cisco Unified Communications Manager | =4.1\(3\) | |
Cisco Unified Communications Manager | =6.1 | |
Cisco Unified Communications Manager | =4.2 | |
Cisco Unified Communications Manager | =4.3 | |
Cisco Unified Communications Manager | =4.2.3 | |
Cisco Unified Communications Manager | =4.1\(3\)sr4 | |
Cisco Unified Communications Manager | =4.2.1 | |
Cisco Unified Communications Manager | =4.1.3 | |
Cisco Unified Communications Manager | =4.1-\(3\)sr.5 | |
Cisco Unified Communications Manager | =4.3-4.3\(1\)sr.1 | |
Cisco Unified Communications Manager | =6.1\(1\) | |
Cisco Unified Communications Manager | =8.0 | |
Cisco Unified Communications Manager | =4.2-4.2_\(3\)sr2b | |
Cisco Unified Communications Manager | =4.2_3sr1 | |
Cisco Unified Communications Manager | =4.2-4.2\(3\)sr.2 | |
Cisco Unified Communications Manager | =4.2\(3\)sr1 | |
Cisco Unified Communications Manager | =4.3\(1\)sr.1 | |
Cisco Unified Communications Manager | =4.2-4.2_\(3\)sr3 | |
Cisco Unified Communications Manager | =7.0\(1\) | |
Cisco Unified Communications Manager | =4.2\(3\)sr4 | |
Cisco Unified Communications Manager | =4.2.2 | |
Cisco Unified Communications Manager | =4.3\(1\) | |
Cisco Unified Communications Manager | =4.1\(3\)sr3 | |
Cisco Unified Communications Manager | =6.1\(1b\) | |
Cisco Unified Communications Manager | =4.1 | |
Cisco Unified Communications Manager | =6.0\(1a\) | |
Cisco Unified Communications Manager | =4.2_3 | |
Cisco Unified Communications Manager | =7.0 | |
Cisco Unified Communications Manager | =4.1-\(3\)sr4 | |
Cisco Unified Communications Manager | =4.3.1 | |
Cisco Unified Communications Manager | =4.3\(2\) | |
Cisco Unified Communications Manager | =6.1\(2\)su1 | |
Cisco Unified Communications Manager | =6.0 | |
Cisco Unified Communications Manager | =4.2\(3\)sr3 | |
Cisco Unified Communications Manager | =4.2.3sr2b | |
Cisco Unified Communications Manager | =6.1\(1a\) | |
Cisco Unified Communications Manager | =7.0\(2\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0592 is classified as a denial of service vulnerability that can severely impact the functionality of Cisco Unified Communications Manager.
To mitigate CVE-2010-0592, upgrade Cisco Unified Communications Manager to versions 4.3(2)sr1a, 6.1(3), 7.0(2), 7.1(2), or 8.0(1) or later.
CVE-2010-0592 affects multiple versions including 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), and 8.x before 8.0(1).
Yes, CVE-2010-0592 can be exploited remotely by sending a malformed message to the CTI Manager service.
Exploitation of CVE-2010-0592 can lead to a denial of service, causing the affected Cisco Unified Communications Manager to stop functioning properly.