Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco...
Vulnerability Description
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2051
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/57453
- http://secunia.com/advisories/36499
- http://www.securityfocus.com/bid/36152
- http://secunia.com/advisories/36498
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080af2d11.shtml
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4a30f.shtml
- http://www.securitytracker.com/id?1022775
More from cisco
View All →Affected Vendor
cisco
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.