7.8
CVE-2010-2840
- EPSS 0.43%
- Published 26.08.2010 21:00:01
- Last modified 11.04.2025 00:51:21
- Source psirt@cisco.com
- Teams watchlist Login
- Open Login
The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message, which allows remote attackers to cause a denial of service (process failure) via a malformed message, aka Bug ID CSCtd39629.
Data is provided by the National Vulnerability Database (NVD)
Cisco ≫ Unified Presence Server Version6.0
Cisco ≫ Unified Presence Server Version7.0
Cisco ≫ Unified Presence Server Version6.0.5.1102-1
Cisco ≫ Unified Presence Server Version7.0.3.10102-3
Cisco ≫ Unified Presence Server Version7.0.3.10103-2
Cisco ≫ Unified Presence Server Version7.0.4.10101-2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.43% | 0.594 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.