CVE-2011-2561: High severity cisco unified communications solutions vulnerability
The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termination Point (MTP), which allows remote attackers to cause a denial of service (service outage) via a crafted call, aka Bug ID CSCtc61990.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2561?
CVE-2011-2561 has been rated as a medium severity vulnerability.
How do I fix CVE-2011-2561?
To fix CVE-2011-2561, upgrade to the versions of Cisco Unified Communications Manager specified in Cisco's security advisory.
What are the affected versions for CVE-2011-2561?
CVE-2011-2561 affects Cisco Unified Communications Manager versions prior to 7.1(5b)su4 and 8.0(1).
What kind of attack does CVE-2011-2561 enable?
CVE-2011-2561 allows remote attackers to exploit vulnerabilities in SIP call handling to potentially execute arbitrary code.
Is CVE-2011-2561 exploitable from the internet?
Yes, CVE-2011-2561 can be exploited by remote attackers, potentially allowing for unauthorized access.