CVE-2007-1826
Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the IPSec Manager Service for Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allows remote attackers to cause a denial of service (loss of cluster services) via a "specific UDP packet" to UDP port 8500, aka bug ID CSCsg60949.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 1.98% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- cisco/unified callmanager · cisco/unified presence server
- Source
- cve@mitre.org
References
- http://osvdb.org/34919
- http://secunia.com/advisories/24690Patch, Vendor Advisory
- http://securitytracker.com/id?1017826Patch
- http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/23181Patch
- http://www.vupen.com/english/advisories/2007/1144
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33302
- http://osvdb.org/34919
- http://secunia.com/advisories/24690Patch, Vendor Advisory
- http://securitytracker.com/id?1017826Patch
- http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/23181Patch
- http://www.vupen.com/english/advisories/2007/1144
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33302
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.