Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8q52-6xmp-rvx5

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.

The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.

EPSS

Процентиль: 62%
0.00427
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 15 лет назад

The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.

EPSS

Процентиль: 62%
0.00427
Низкий

Дефекты

CWE-20