CVE-2013-3461: High severity Cisco Unified Communications Manager vulnerability
Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service disruption) via a flood of UDP packets to port 5060, aka Bug ID CSCub35869.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3461?
CVE-2013-3461 has a moderate severity level as it can lead to denial of service through excessive SIP packet flooding.
How do I fix CVE-2013-3461?
To fix CVE-2013-3461, ensure you update your Cisco Unified Communications Manager to the appropriate patched version.
What versions are affected by CVE-2013-3461?
CVE-2013-3461 affects Cisco Unified Communications Manager versions 8.5, 8.6, and certain 9.x versions prior to the recommended updates.
What vulnerabilities does CVE-2013-3461 exploit?
CVE-2013-3461 exploits improper SIP packet rate limiting, allowing attackers to flood the target with UDP packets.
What are the potential impacts of CVE-2013-3461?
The potential impacts of CVE-2013-3461 include memory and CPU consumption, leading to service disruption on the affected system.