CVE-2010-2840 Information
Feb 14, 2021
cve
Description
The Presence Engine (PE) service in Cisco Unified Presence 6.x before 6.0(7) and 7.x before 7.0(8) does not properly handle an erroneous Contact field in the header of a SIP SUBSCRIBE message which allows remote attackers to cause a denial of service (process failure) via a malformed message aka Bug ID CSCtd39629.
Reference
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b43909.shtml http://www.vupen.com/english/advisories/2010/2186
Share on: