Cisco Unified Communications Manager SIP Memory Leak DoS (CSCuv39370)

high Nessus Plugin ID 90312

Synopsis

The remote device is affected by denial of service vulnerability.

Description

According to its self-reported version, the Cisco Unified Communications Manager (CUCM) running on the remote device is affected by a denial of service vulnerability in the Session Initiation Protocol (SIP) gateway implementation due to improper handling of malformed SIP messages. An unauthenticated, remote attacker can exploit this, via crafted SIP messages, to cause memory leakage, resulting in an eventual reload of the affected device.

Solution

Upgrade to Cisco Unified Communications Manager version 9.1(2)SU4 / 10.5(2)SU3 / 11.0(1)SU1 or later.

See Also

http://www.nessus.org/u?ddc3f527

https://quickview.cloudapps.cisco.com/quickview/bug/CSCuv39370

Plugin Details

Severity: High

ID: 90312

File Name: cisco_cucm_a-20160323-sip.nasl

Version: 1.10

Type: combined

Family: CISCO

Published: 4/1/2016

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:unified_communications_manager

Required KB Items: Host/Cisco/CUCM/Version, Host/Cisco/CUCM/Version_Display

Exploit Ease: No known exploits are available

Patch Publication Date: 3/23/2016

Vulnerability Publication Date: 3/23/2016

Reference Information

CVE: CVE-2016-1350

BID: 85372

CISCO-SA: cisco-sa-20160323-sip

CISCO-BUG-ID: CSCuv39370