CVE-2013-1220

high
Published 2013-05-09 · Modified 2026-04-29
CVSS v3
CVSS v2
7.8
VIR risk
7.8

Description

The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp

Application impact

VendorProductVersionsFixed
ciscounified_customer_voice_portal{"endIncluding":"9.0\\(1\\)"}
ciscounified_customer_voice_portal3.0
ciscounified_customer_voice_portal3.6\(10\)
ciscounified_customer_voice_portal4.0
ciscounified_customer_voice_portal4.0\(2\)
ciscounified_customer_voice_portal4.1
ciscounified_customer_voice_portal7.0
ciscounified_customer_voice_portal7.0\(2\)
ciscounified_customer_voice_portal8.0\(1\)
ciscounified_customer_voice_portal8.5\(1\)
ciscounified_customer_voice_portal9.0

References

Verify integrity in audit chain (admin only). AS-IS.