CVE-2015-0613: High severity Cisco Unity Connection vulnerability
The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul20444.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0613?
CVE-2015-0613 has a high severity rating due to its potential to enable remote denial of service attacks.
How do I fix CVE-2015-0613?
To fix CVE-2015-0613, upgrade to the latest patched version of Cisco Unity Connection.
Which versions are affected by CVE-2015-0613?
CVE-2015-0613 affects Cisco Unity Connection versions prior to 8.5(1)SU7, 8.6(2a)SU4, 9.1(2)SU2, and 10.0(1)SU1.
What type of attack does CVE-2015-0613 enable?
CVE-2015-0613 enables remote attackers to cause a denial of service via a malformed SIP request.
Is there a workaround for CVE-2015-0613?
There is no documented workaround for CVE-2015-0613; the best mitigation is to apply the appropriate software updates.