7.8
CVSSv2

CVE-2010-2825

Published: 17/08/2010 Updated: 26/07/2011
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Unspecified vulnerability in the SIP inspection feature on the Cisco Application Control Engine (ACE) Module with software A2(1.x) before A2(1.6), A2(2.x) before A2(2.3), and A2(3.x) before A2(3.1) for Catalyst 6500 series switches and 7600 series routers, and the Cisco Application Control Engine (ACE) 4710 appliance with software before A3(2.4), allows remote malicious users to cause a denial of service (device reload) via crafted SIP packets over (1) TCP or (2) UDP, aka Bug IDs CSCta65603 and CSCta71569.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ace_module

cisco ace 4710 a1\\(8.0\\)

cisco ace 4710

cisco ace 4710 a1\\(2.0\\)

cisco ace 4710 a1\\(2.3\\)

cisco ace 4710 a3\\(2.0\\)

cisco ace 4710 a3\\(1.0\\)

Vendor Advisories

The Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine contain the following DoS vulnerabilities: Real-Time Streaming Protocol (RTSP) inspection DoS vulnerability HTTP, RTSP, and Session Initiation Protocol (SIP) inspection DoS vulnerability Secure Socket Layer (SSL) DoS vulner ...