ID

VAR-201302-0391


CVE

CVE-2013-1133


TITLE

Cisco Unified Communications Manager Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2012-005958

DESCRIPTION

Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and 9.x before 9.0(1) allows remote attackers to cause a denial of service (CPU consumption and GUI and voice outages) via malformed packets to unused UDP ports, aka Bug ID CSCtx43337. Successful exploits could allow a remote attacker to trigger a memory leak or cause denial of service condition resulting in the interruption of voice services. This issue is documented by the Cisco bug ID CSCtx43337. This component provides a scalable, distributed and highly available enterprise IP telephony call processing solution

Trust: 1.98

sources: NVD: CVE-2013-1133 // JVNDB: JVNDB-2012-005958 // BID: 58219 // VULHUB: VHN-61135

AFFECTED PRODUCTS

vendor:ciscomodel:unified communications managerscope:eqversion:8.6

Trust: 1.9

vendor:ciscomodel:unified communications managerscope:eqversion:8.6\(2\)

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:8.6\(2a\)

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:8.6\(1\)

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:8.6\(2a\)su1

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:8.6\(4\)

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:8.6\(1a\)

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:eqversion:9.0\(1\)

Trust: 1.6

vendor:ciscomodel:unified communications managerscope:ltversion:8.6

Trust: 0.8

vendor:ciscomodel:unified communications managerscope:eqversion:9.0(1)

Trust: 0.8

vendor:ciscomodel:unified communications managerscope:ltversion:9.x

Trust: 0.8

vendor:ciscomodel:unified communications managerscope:eqversion:8.6(4) be3k

Trust: 0.8

vendor:ciscomodel:unified communications managerscope:eqversion:8.6(2a)su2

Trust: 0.8

vendor:ciscomodel:unified communications managerscope:ltversion:8.6 be3k

Trust: 0.8

vendor:ciscomodel:unified communications manager 8.6 su1scope: - version: -

Trust: 0.3

vendor:ciscomodel:unified communications managerscope:neversion:8.0(1)

Trust: 0.3

sources: BID: 58219 // JVNDB: JVNDB-2012-005958 // CNNVD: CNNVD-201302-601 // NVD: CVE-2013-1133

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1133
value: HIGH

Trust: 1.0

NVD: CVE-2013-1133
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201302-601
value: HIGH

Trust: 0.6

VULHUB: VHN-61135
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-1133
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-61135
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-61135 // JVNDB: JVNDB-2012-005958 // CNNVD: CNNVD-201302-601 // NVD: CVE-2013-1133

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-61135 // JVNDB: JVNDB-2012-005958 // NVD: CVE-2013-1133

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201302-601

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201302-601

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-005958

PATCH

title:cisco-sa-20130227-cucmurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130227-cucm

Trust: 0.8

title:cisco-sa-20130227-cucmurl:http://www.cisco.com/cisco/web/support/JP/111/1117/1117487_cisco-sa-20130227-cucm-j.html

Trust: 0.8

sources: JVNDB: JVNDB-2012-005958

EXTERNAL IDS

db:NVDid:CVE-2013-1133

Trust: 2.8

db:JVNDBid:JVNDB-2012-005958

Trust: 0.8

db:CNNVDid:CNNVD-201302-601

Trust: 0.7

db:CISCOid:20130227 CISCO UNIFIED COMMUNICATIONS MANAGER MULTIPLE DENIAL OF SERVICE VULNERABILITIES

Trust: 0.6

db:BIDid:58219

Trust: 0.4

db:VULHUBid:VHN-61135

Trust: 0.1

sources: VULHUB: VHN-61135 // BID: 58219 // JVNDB: JVNDB-2012-005958 // CNNVD: CNNVD-201302-601 // NVD: CVE-2013-1133

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20130227-cucm

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1133

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1133

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-61135 // BID: 58219 // JVNDB: JVNDB-2012-005958 // CNNVD: CNNVD-201302-601 // NVD: CVE-2013-1133

CREDITS

Reported by vendor.

Trust: 0.3

sources: BID: 58219

SOURCES

db:VULHUBid:VHN-61135
db:BIDid:58219
db:JVNDBid:JVNDB-2012-005958
db:CNNVDid:CNNVD-201302-601
db:NVDid:CVE-2013-1133

LAST UPDATE DATE

2024-11-23T21:45:49.166000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-61135date:2013-03-04T00:00:00
db:BIDid:58219date:2013-02-28T00:00:00
db:JVNDBid:JVNDB-2012-005958date:2013-03-01T00:00:00
db:CNNVDid:CNNVD-201302-601date:2013-02-28T00:00:00
db:NVDid:CVE-2013-1133date:2024-11-21T01:48:57.957

SOURCES RELEASE DATE

db:VULHUBid:VHN-61135date:2013-02-27T00:00:00
db:BIDid:58219date:2013-02-28T00:00:00
db:JVNDBid:JVNDB-2012-005958date:2013-03-01T00:00:00
db:CNNVDid:CNNVD-201302-601date:2013-02-28T00:00:00
db:NVDid:CVE-2013-1133date:2013-02-27T21:55:04.107