Описание
The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a Plantronics headset, aka Bug ID CSCti40315.
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:cisco:ip_communicator:7.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ip_communicator:7.0\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:ip_communicator:7.0\(2\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:ip_communicator:7.0\(3\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:ip_communicator:7.0\(4\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:ip_communicator:7.0\(5\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:ip_communicator:7.0\(6\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:ip_communicator:8.6:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00474
Низкий
5 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
почти 4 года назад
The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a Plantronics headset, aka Bug ID CSCti40315.
EPSS
Процентиль: 64%
0.00474
Низкий
5 Medium
CVSS2
Дефекты
CWE-264