PT-2016-4814 · Cisco · Cisco Unified Communications Manager Im/Presence Service

Published

2016-08-08

·

Updated

2017-08-16

·

CVE-2016-1466

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified Communications Manager IM and Presence Service versions 9.1(1) SU6 through 9.1(1) SU7, 10.5(2) SU2 through 10.5(2) SU2a, 11.0(1) SU1, 11.5(1)
Description The issue allows remote attackers to cause a denial of service, resulting in the restart of the sipd process, by sending crafted headers in a SIP packet.
Recommendations For versions 9.1(1) SU6 through 9.1(1) SU7, update to a version that fixes the issue. For versions 10.5(2) SU2 through 10.5(2) SU2a, update to a version that fixes the issue. For version 11.0(1) SU1, update to a version that fixes the issue. For version 11.5(1), update to a version that fixes the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1466

Affected Products

Cisco Unified Communications Manager Im/Presence Service