CVE-2015-0615
Description
The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (port consumption) by improperly terminating SIP sessions, aka Bug ID CSCul28089.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | unity_connection | 8.5\(1\) | |
| cisco | unity_connection | 8.5\(1\)su1 | |
| cisco | unity_connection | 8.5\(1\)su2 | |
| cisco | unity_connection | 8.5\(1\)su3 | |
| cisco | unity_connection | 8.5\(1\)su4 | |
| cisco | unity_connection | 8.5\(1\)su5 | |
| cisco | unity_connection | 8.5\(1\)su6 | |
| cisco | unity_connection | 8.5_base | |
| cisco | unity_connection | 8.6\(1\) | |
| cisco | unity_connection | 8.6\(1a\) | |
| cisco | unity_connection | 8.6\(2\) | |
| cisco | unity_connection | 8.6\(2a\) | |
| cisco | unity_connection | 8.6\(2a\)su1 | |
| cisco | unity_connection | 8.6\(2a\)su2 | |
| cisco | unity_connection | 8.6\(2a\)su3 | |
| cisco | unity_connection | 8.6_base | |
| cisco | unity_connection | 9.0\(1\) | |
| cisco | unity_connection | 9.1\(1\) | |
| cisco | unity_connection | 9.1\(2\) | |
| cisco | unity_connection | 10.0.0 | |
| cisco | unity_connection | 10.0.5 | |
References
CWEs
CWE-19
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.