7.8
CVSSv2

CVE-2009-2051

Published: 27/08/2009 Updated: 06/10/2021
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS 12.2 up to and including 12.4 and 15.0 up to and including 15.1, Cisco IOS XE 2.5.x and 2.6.x prior to 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x prior to 5.1(3g), 6.x prior to 6.1(4), and 7.x prior to 7.1(2) allow remote malicious users to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager

cisco ios

cisco ios xe

Vendor Advisories

Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS® Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device when SIP operation is enabled Cisco has released software updates that address these vulnerabilities There are no workarounds for devices that ...
Cisco Unified Communications Manager (formerly CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption to voice services The Session Initiation Protocol (SIP) and Skinny Client Control Protocol (SCCP) services are affected by these vulnerabilities Cisco has released free sof ...