CVE-2015-0612 describes a denial-of-service vulnerability in the Connection Conversation Manager (CuCsMgr) process of Cisco Unity Connection versions 8.5, 8.6, and 9.x when SIP trunk integration is enabled. An unauthenticated remote attacker can exploit this flaw by sending a crafted UDP packet, leading to a SIP outage. This vulnerability has a CVSS score of 7.1 (High), indicating a high impact on availability with medium attack complexity. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.5\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:8.5\(1\):*:*:*:*:*:*:* | ||
8.5\(1\)su1CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:8.5\(1\)su1:*:*:*:*:*:*:* | ||
8.5\(1\)su2CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:8.5\(1\)su2:*:*:*:*:*:*:* | ||
8.5\(1\)su3CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:8.5\(1\)su3:*:*:*:*:*:*:* | ||
8.5\(1\)su4CPE matchmatch criteria | cpe:2.3:a:cisco:unity_connection:8.5\(1\)su4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.