Cisco Unified Communications Manager DoS (cisco-sa-cucm-dos-kkHq43We)

high Nessus Plugin ID 206152

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco Unified Communications Manager running on the report host is affected by a denial of service (DoS) vulnerability. Due to improper processing of SIP messages, an unauthenticated, remote, attacker can cause the system to reload and thus stop responding.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCwi68892

See Also

http://www.nessus.org/u?9a5349ae

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwi68892

Plugin Details

Severity: High

ID: 206152

File Name: cisco-sa-cucm-dos-kkHq43We.nasl

Version: 1.3

Type: combined

Family: CISCO

Published: 8/23/2024

Updated: 11/8/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2024-20375

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:unified_communications_manager

Required KB Items: Host/Cisco/CUCM/Version, Host/Cisco/CUCM/Version_Display

Exploit Ease: No known exploits are available

Patch Publication Date: 8/21/2024

Vulnerability Publication Date: 8/21/2024

Reference Information

CVE: CVE-2024-20375

CISCO-SA: cisco-sa-cucm-dos-kkHq43We

IAVA: 2024-A-0517-S

CISCO-BUG-ID: CSCwi68892