Cisco Unified CM/SME Vulnerability Could Lead to Denial of Service
CVE-2024-20375
8.6HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 21 August 2024
Summary
A vulnerability exists in the SIP call processing feature of Cisco Unified Communications Manager and the Session Management Edition. This flaw stems from improper parsing of SIP messages, allowing an attacker to send specially crafted SIP messages to impacted devices. Exploitation of this vulnerability may lead to a denial of service (DoS), causing the affected device to reload, thereby disrupting voice and video communications. Organizations using these Cisco products must ensure they are up to date with security configurations to mitigate this risk.
Affected Version(s)
Cisco Unified Communications Manager 12.0(1)SU1
Cisco Unified Communications Manager 12.0(1)SU2
Cisco Unified Communications Manager 12.0(1)SU3
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved