7.8

CVE-2008-1744

The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Unified Callmanager Version 4.1
Cisco ≫ Unified Callmanager Version 4.1_3_sr4
Cisco ≫ Unified Callmanager Version 4.1_3_sr5
Cisco ≫ Unified Callmanager Version 4.1_3_sr5b
Cisco ≫ Unified Callmanager Version 4.1_3_sr5c
Cisco ≫ Unified Communications Manager Version 4.2_3_sr2
Cisco ≫ Unified Communications Manager Version 4.2_3_sr2b
Cisco ≫ Unified Communications Manager Version 4.2_3_sr3
Cisco ≫ Unified Communications Manager Version 4.3_1_sr1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.636
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/30238
http://securitytracker.com/id?1020022
http://www.cisco.com/en/US/products/products_security_advisory09186a0080995688.shtml
http://www.securityfocus.com/bid/29221
http://www.vupen.com/english/advisories/2008/1533
https://exchange.xforce.ibmcloud.com/vulnerabilities/42415