CVE-2009-2051

high Cisco
CVSS v3 Base Score
7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS Score
1.7%
Exploitation probability in 30 days
Top 18% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
None
Availability
C
Published: August 27, 2009 (6103 days ago)
Last Modified: April 23, 2026
Vendor: Cisco
Source: NVD

Description

Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.

CWE

NVD-CWE-Other

Affected Products

cisco unified communications managercisco ioscisco ios xe

References