CVE-2012-3949
Last modified
CVE-2012-3949 is a vulnerability of currently unknown severity. The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.. EPSS estimates a 3.20% chance of exploitation in the next 30 days.
Description
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Manager | 6.0\(1a\) |
| Cisco | Unified Communications Manager | 6.0\(1b\) |
| Cisco | Unified Communications Manager | 6.1\(1\) |
| Cisco | Unified Communications Manager | 6.1\(1a\) |
| Cisco | Unified Communications Manager | 6.1\(1b\) |
| Cisco | Unified Communications Manager | 6.1\(2\) |
| Cisco | Unified Communications Manager | 6.1\(3\) |
| Cisco | Unified Communications Manager | 6.1\(3a\) |
| Cisco | Unified Communications Manager | 6.1\(3b\) |
| Cisco | Unified Communications Manager | 6.1\(4\) |
| Cisco | Unified Communications Manager | 6.1\(4a\) |
| Cisco | Unified Communications Manager | 6.1\(4b\) |
| Cisco | Unified Communications Manager | 6.1\(5\) |
| Cisco | Unified Communications Manager | 7.1\(1\) |
| Cisco | Unified Communications Manager | 7.1\(2\) |
| Cisco | Unified Communications Manager | 7.1\(2a\) |
| Cisco | Unified Communications Manager | 7.1\(2b\) |
| Cisco | Unified Communications Manager | 7.1\(3\) |
| Cisco | Unified Communications Manager | 7.1\(3a\) |
| Cisco | Unified Communications Manager | 7.1\(3b\) |
| Cisco | Unified Communications Manager | 7.1\(5\) |
| Cisco | Unified Communications Manager | 7.1\(5a\) |
| Cisco | Unified Communications Manager | 7.1\(5b\) |
| Cisco | Unified Communications Manager | 7.1\(5b\)su1 |
| Cisco | Unified Communications Manager | 7.1\(5b\)su1a |
| Cisco | Unified Communications Manager | 7.1\(5b\)su2 |
| Cisco | Unified Communications Manager | 7.1\(5b\)su3 |
| Cisco | Unified Communications Manager | 7.1\(5b\)su4 |
| Cisco | Unified Communications Manager | 8.0 |
| Cisco | Unified Communications Manager | 8.0\(1\) |
| Cisco | Unified Communications Manager | 8.0\(2\) |
| Cisco | Unified Communications Manager | 8.0\(2a\) |
| Cisco | Unified Communications Manager | 8.0\(2b\) |
| Cisco | Unified Communications Manager | 8.0\(2c\) |
| Cisco | Unified Communications Manager | 8.0\(3\) |
| Cisco | Unified Communications Manager | 8.0\(3a\) |
| Cisco | Unified Communications Manager | 8.5\(1\)su1 |
| Cisco | Unified Communications Manager | 8.5\(1\)su2 |
| Cisco | Unified Communications Manager | 8.5\(1\)su3 |
| Cisco | Ios | 12.2 |
| Cisco | Ios | 12.2b |
| Cisco | Ios | 12.2bc |
| Cisco | Ios | 12.2bw |
| Cisco | Ios | 12.2bx |
| Cisco | Ios | 12.2by |
| Cisco | Ios | 12.2bz |
| Cisco | Ios | 12.2ca |
| Cisco | Ios | 12.2cx |
| Cisco | Ios | 12.2cy |
| Cisco | Ios | 12.2cz |
Showing 50 of 260 affected configurations. See NVD for the full list.
References
- http://osvdb.org/85816Broken Link
- http://secunia.com/advisories/50774Not Applicable
- http://www.securityfocus.com/bid/55697Third Party Advisory, VDB Entry
- http://osvdb.org/85816Broken Link
- http://secunia.com/advisories/50774Not Applicable
- http://www.securityfocus.com/bid/55697Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-3949?
How severe is CVE-2012-3949?
How do I fix CVE-2012-3949?
Are you affected by CVE-2012-3949?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
