CVE-2010-2837: High severity Cisco Unified Communications Manager vulnerability
The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.1SU before 6.1(5)SU1, 7.0SU before 7.0(2a)SU3, 7.1SU before 7.1(3b)SU2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtd17310.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2837?
CVE-2010-2837 has a severity rating that indicates potential denial of service vulnerabilities in Cisco Unified Communications Manager.
How do I fix CVE-2010-2837?
To fix CVE-2010-2837, upgrade your Cisco Unified Communications Manager to a version that is not vulnerable, such as 6.1(5)SU1 or later.
What software versions are affected by CVE-2010-2837?
CVE-2010-2837 affects Cisco Unified Communications Manager versions prior to specific updates, including 6.1SU, 7.0SU, and 8.0.
What are the potential impacts of CVE-2010-2837?
The potential impact of CVE-2010-2837 includes process failure, leading to denial of service for users of Cisco Unified Communications Manager.
Is there a workaround for CVE-2010-2837 while waiting for a fix?
Currently, there are no known workarounds for CVE-2010-2837, so upgrading is recommended for protection.