CVE-2015-0616: High severity Cisco Unity Connection vulnerability
The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) by improperly terminating SIP TCP connections, aka Bug ID CSCul69819.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0616?
CVE-2015-0616 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2015-0616?
To fix CVE-2015-0616, you should upgrade your Cisco Unity Connection software to the recommended versions that include the security patches.
What happens if CVE-2015-0616 is exploited?
If CVE-2015-0616 is exploited, it could allow remote attackers to crash the system, resulting in a core dump and restart of the affected service.
Which Cisco Unity Connection versions are vulnerable to CVE-2015-0616?
CVE-2015-0616 affects Cisco Unity Connection versions 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2.
Is there a workaround for CVE-2015-0616 until I can apply a patch?
Currently, there is no specific workaround for CVE-2015-0616; applying the recommended updates is the most effective mitigation.