CVE-2013-1133
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and 9.x before 9.0(1) allows remote attackers to cause a denial of service (CPU consumption and GUI and voice outages) via malformed packets to unused UDP ports, aka Bug ID CSCtx43337.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130227-cucm
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | unified_communications_manager | 8.6 | |
| cisco | unified_communications_manager | 8.6\(1\) | |
| cisco | unified_communications_manager | 8.6\(1a\) | |
| cisco | unified_communications_manager | 8.6\(2\) | |
| cisco | unified_communications_manager | 8.6\(2a\) | |
| cisco | unified_communications_manager | 8.6\(2a\)su1 | |
| cisco | unified_communications_manager | 8.6\(4\) | |
| cisco | unified_communications_manager | 9.0\(1\) | |
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.