CVE-2007-1833
The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice…
Does this matter?
Lower severity and a low EPSS score (2.35%). Track it; it rarely justifies an emergency change on its own.
Description
The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice services) by sending crafted packets to the (1) SCCP (2000/tcp) or (2) SCCPS (2443/tcp) port.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.35% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- cisco/unified callmanager
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24665Patch, Vendor Advisory
- http://securitytracker.com/id?1017826Patch
- http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/23181
- http://www.vupen.com/english/advisories/2007/1144
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33295
- http://secunia.com/advisories/24665Patch, Vendor Advisory
- http://securitytracker.com/id?1017826Patch
- http://www.cisco.com/warp/public/707/cisco-sa-20070328-voip.shtmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/23181
- http://www.vupen.com/english/advisories/2007/1144
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33295
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.