CVE-2015-0615: High severity Cisco Unity Connection vulnerability
The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (port consumption) by improperly terminating SIP sessions, aka Bug ID CSCul28089.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0615?
CVE-2015-0615 is classified as a denial of service vulnerability due to SIP session mismanagement.
How do I fix CVE-2015-0615?
To fix CVE-2015-0615, you should upgrade your Cisco Unity Connection to a version that is not affected by this vulnerability, specifically 8.5(1)SU7, 8.6(2a)SU4, 9.1(2)SU2, or 10.0(1)SU1 and above.
What versions of Cisco Unity Connection are affected by CVE-2015-0615?
CVE-2015-0615 affects Cisco Unity Connection versions 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1.
Is remote exploitation possible with CVE-2015-0615?
Yes, remote attackers can exploit CVE-2015-0615 to cause a denial of service through port consumption.
What type of attack does CVE-2015-0615 facilitate?
CVE-2015-0615 facilitates denial of service attacks by improperly terminating SIP sessions.