7.8
CVE-2010-2840
- EPSS 0.43%
- Veröffentlicht 26.08.2010 21:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Unified Presence Server Version6.0
Cisco ≫ Unified Presence Server Version7.0
Cisco ≫ Unified Presence Server Version6.0.5.1102-1
Cisco ≫ Unified Presence Server Version7.0.3.10102-3
Cisco ≫ Unified Presence Server Version7.0.3.10103-2
Cisco ≫ Unified Presence Server Version7.0.4.10101-2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.43% | 0.594 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.