Cisco Unified Communications Manager SCCP Registration may Cause Reload
9 Mar. 2012
Summary
Cisco Unified Communication Manager may reload when a specially crafted SCCP message is processed. Successful exploitation could cause a loss of all voice services that are being handled by the affected device.
Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allow remote attackers to cause a denial of service (device reload) via a crafted SCCP registration, aka Bug ID CSCtu73538.
Vendor Status:
Cisco has released free software updates that address this vulnerability.