CVE-2019-1887
Last modified
CVE-2019-1887 is a vulnerability of currently unknown severity. A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of input SIP traffic. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of input SIP traffic. An attacker could exploit this vulnerability by sending a malformed SIP packet to an affected Cisco Unified Communications Manager. A successful exploit could allow the attacker to trigger a new registration process on all connected phones, temporarily disrupting service.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Communications Manager | 10.5\(2.10000.5\) |
| Cisco | Unified Communications Manager | 11.5\(1.10000.6\) |
| Cisco | Unified Communications Manager | 12.0\(1.10000.10\) |
| Cisco | Unified Communications Manager | 12.5\(1.10000.22\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1887?
How severe is CVE-2019-1887?
How do I fix CVE-2019-1887?
Are you affected by CVE-2019-1887?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
