CVE-2012-3060: High severity Cisco Unity Connection vulnerability
Published Sep 16, 2012
·Updated
Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269.
Affected Software
3 affected components
Cisco Unity Connection=8.6
Cisco Unity Connection=9.0
Cisco Unity Connection=9.5
Event History
Sep 16, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3060?
CVE-2012-3060 has a moderate severity as it can lead to a denial of service due to CPU consumption.
2
How do I fix CVE-2012-3060?
To fix CVE-2012-3060, upgrade Cisco Unity Connection to a version that is not affected, such as 9.6 or later.
3
What versions of Cisco Unity Connection are affected by CVE-2012-3060?
CVE-2012-3060 affects Cisco Unity Connection versions 8.6, 9.0, and 9.5.
4
Can CVE-2012-3060 be exploited remotely?
Yes, CVE-2012-3060 can be exploited remotely through malformed UDP packets.
5
What type of attack does CVE-2012-3060 facilitate?
CVE-2012-3060 facilitates a denial of service attack by causing excessive CPU consumption on the affected device.