SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-1743

Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption)…

HIGH 7.8EPSS 1.50%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, aka Bug ID CSCsi98433.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS
1.50% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-399
Affected
cisco/unified communications manager
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.