CVE-2011-1604: High severity cisco unified communications solutions vulnerability
Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (memory consumption and process failure) via a malformed SIP message, aka Bug ID CSCti42904.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1604?
CVE-2011-1604 has a medium severity rating as it can lead to denial of service conditions.
How do I fix CVE-2011-1604?
To fix CVE-2011-1604, upgrade your Cisco Unified Communications Manager to version 6.1(5)su3 or later.
Which versions of Cisco Unified Communications Manager are affected by CVE-2011-1604?
CVE-2011-1604 affects versions 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1).
What kind of attack does CVE-2011-1604 enable?
CVE-2011-1604 allows remote attackers to cause denial of service by sending malformed SIP messages.
Are there any workarounds for CVE-2011-1604?
There are currently no documented workarounds for CVE-2011-1604, so upgrading is recommended.