CVE-2010-4686

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
07/01/2011
Last modified:
11/04/2025

Description

CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" request size, which allows remote attackers to cause a denial of service (memory consumption) by sending this traffic over a long duration, aka Bug ID CSCtb47950.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* 15.0\(1\)xa1 (excluding)