HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2024-20375

CVSS 8.6v3.1pub. 2024-08-21upd. 2025-08-01

A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper parsing of SIP messages. An attacker could exploit this vulnerability by sending a crafted SIP message to an affected Cisco Unified CM or Cisco Unified CM SME device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition that interrupts the communications of reliant voice and video devices.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • Cisco Unified Communications Manager

    APP
    Cisco
    12.0\(1\)su112.0\(1\)su212.0\(1\)su312.0\(1\)su412.0\(1\)su512.5\(1\)12.5\(1\)su112.5\(1\)su212.5\(1\)su312.5\(1\)su412.5\(1\)su512.5\(1\)su612.5\(1\)su712.5\(1\)su7a12.5\(1\)su8+ 1 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2025-20309CRITICAL10.0PL ✓same product

Cisco Unified CM — statyczne dane logowania root umożliwiają pełne przejęcie systemu

CVE-2024-20253CRITICAL9.9PL ✓same product

RCE w produktach Cisco Unified Communications — eskalacja do root

CVE-2017-12337CRITICAL9.8PL ✓same product

Cisco Voice OS – nieautoryzowany dostęp root po upgrade'ie (Auth Bypass)

CVE-2026-20230HIGH8.6⚠ KEVsame product

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager ...

CVE-2026-20045HIGH8.2⚠ KEVsame product

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Ses...