CVE-2014-3337

medium Cisco
CVSS v3 Base Score
6.8
AV:N/AC:L/Au:S/C:N/I:N/A:C
EPSS Score
1.8%
Exploitation probability in 30 days
Top 17% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
None
Availability
C
Published: August 12, 2014 (4292 days ago)
Last Modified: May 6, 2026
Vendor: Cisco
Source: NVD

Description

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428.

CWE

CWE-20

Affected Products

cisco unified communications domain manager

References