CVE-2015-0614
Last modified
CVE-2015-0614 is a vulnerability of currently unknown severity. The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.. EPSS estimates a 1.68% chance of exploitation in the next 30 days.
Description
The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unity Connection | 8.5\(1\) |
| Cisco | Unity Connection | 8.5\(1\)su1 |
| Cisco | Unity Connection | 8.5\(1\)su2 |
| Cisco | Unity Connection | 8.5\(1\)su3 |
| Cisco | Unity Connection | 8.5\(1\)su4 |
| Cisco | Unity Connection | 8.5\(1\)su5 |
| Cisco | Unity Connection | 8.5\(1\)su6 |
| Cisco | Unity Connection | 8.5_base |
| Cisco | Unity Connection | 8.6\(1\) |
| Cisco | Unity Connection | 8.6\(1a\) |
| Cisco | Unity Connection | 8.6\(2\) |
| Cisco | Unity Connection | 8.6\(2a\) |
| Cisco | Unity Connection | 8.6\(2a\)su1 |
| Cisco | Unity Connection | 8.6\(2a\)su2 |
| Cisco | Unity Connection | 8.6\(2a\)su3 |
| Cisco | Unity Connection | 8.6_base |
| Cisco | Unity Connection | 9.0\(1\) |
| Cisco | Unity Connection | 9.1\(1\) |
| Cisco | Unity Connection | 9.1\(2\) |
| Cisco | Unity Connection | 10.0.0 |
| Cisco | Unity Connection | 10.0.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0614?
How severe is CVE-2015-0614?
How do I fix CVE-2015-0614?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0608Race condition in the Measurement, Aggregation, and Correlat…
- CVE-2015-0609Race condition in the Common Classification Engine (CCE) in …
- CVE-2015-0610Race condition in the object-group ACL feature in Cisco IOS …
- CVE-2015-0611The administrative web-management portal in Cisco IX 8 (.0.1…
- CVE-2015-0612The Connection Conversation Manager (aka CuCsMgr) process in…
- CVE-2015-0613The Connection Conversation Manager (aka CuCsMgr) process in…
- CVE-2015-0615The call-handling implementation in Cisco Unity Connection 8…
- CVE-2015-0616The Connection Conversation Manager (aka CuCsMgr) process in…
- CVE-2015-0617Cisco ASR 5500 System Architecture Evolution (SAE) Gateway d…
- CVE-2015-0618Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (…
- CVE-2015-0619Memory leak in the embedded web server in the WebVPN subsyst…
- CVE-2015-0620The XML parser in Cisco TelePresence Management Suite (TMS) …
Are you affected by CVE-2015-0614?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
