Vulnerability CVE-2008-3800


Published: 2008-09-26   Modified: 2012-02-12

Description:
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsu38644, a different vulnerability than CVE-2008-3801 and CVE-2008-3802.

Type:

CWE-noinfo

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.1/10
6.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Cisco -> Unified callmanager 
Cisco -> Unified communications manager 
Cisco -> IOS 

 References:
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a0156a.shtml
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a01562.shtml
http://www.vupen.com/english/advisories/2008/2671
http://www.vupen.com/english/advisories/2008/2670
http://www.securityfocus.com/bid/31367
http://secunia.com/advisories/32013
http://secunia.com/advisories/31990
http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6086

Copyright 2024, cxsecurity.com

 

Back to Top