Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-2840

Опубликовано: 26 авг. 2010
Источник: nvd
CVSS2: 7.8
EPSS Низкий

Описание

The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:unified_presence_server:6.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(3\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(4\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(5\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(6\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0\(2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0\(3\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0\(4\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0\(5\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0\(6\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0\(7\):*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:cisco:unified_presence_server:6.0\(2.1101\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(3.1101-2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(4.1101-5\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(5.1101-1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0\(5.1103-2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:6.0.5.1102-1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0.3.10102-3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0.3.10103-2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_presence_server:7.0.4.10101-2:*:*:*:*:*:*:*

EPSS

Процентиль: 62%
0.00427
Низкий

7.8 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
больше 3 лет назад

The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.

EPSS

Процентиль: 62%
0.00427
Низкий

7.8 High

CVSS2

Дефекты

CWE-20