CVE-2010-2840: Input Validation
The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2840?
CVE-2010-2840 has been classified as a high severity vulnerability because it allows remote attackers to cause a denial of service.
How do I fix CVE-2010-2840?
To mitigate CVE-2010-2840, upgrade your Cisco Unified Presence Server to versions 6.0(7), 7.0(8) or later.
What systems are affected by CVE-2010-2840?
CVE-2010-2840 affects Cisco Unified Presence Server versions 6.x before 6.0(7) and 7.x before 7.0(8).
What impact does CVE-2010-2840 have on my Cisco Unified Presence Server?
CVE-2010-2840 can cause process failures resulting in a denial of service condition on affected servers.
Is CVE-2010-2840 easy to exploit?
Yes, CVE-2010-2840 can be exploited by sending a malformed SIP SUBSCRIBE message.