Cisco Unified Communications Manager Denial of Service Vulnerability

Related Vulnerabilities: CVE-2013-5555  

A vulnerability in Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition. The vulnerability is due to improper parsing of a SIP message. An attacker could exploit this vulnerability by sending a specific SIP message to the affected Unified CM. An exploit could allow the attacker to cause a DoS condition, resulting in a coredump and restart of the service. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must be able to send a specific SIP message to the targeted device which may reside on trusted, internal networks behind firewall restrictions. The location of the targeted device could likely reduce the possibility of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.