Cisco Unified CM/SME Vulnerability Could Lead to Denial of Service
CVE-2024-20375

8.6HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 August 2024

Summary

A vulnerability exists in the SIP call processing feature of Cisco Unified Communications Manager and the Session Management Edition. This flaw stems from improper parsing of SIP messages, allowing an attacker to send specially crafted SIP messages to impacted devices. Exploitation of this vulnerability may lead to a denial of service (DoS), causing the affected device to reload, thereby disrupting voice and video communications. Organizations using these Cisco products must ensure they are up to date with security configurations to mitigate this risk.

Affected Version(s)

Cisco Unified Communications Manager 12.0(1)SU1

Cisco Unified Communications Manager 12.0(1)SU2

Cisco Unified Communications Manager 12.0(1)SU3

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.