Vulnerability Intelligence Report
CVE-2010-0581
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:5.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| cisco | ios | 12.3jk, 12.3t, 12.3xd, 12.3xf, 12.3xg, 12.3xi, 12.3xj, 12.3xk, 12.3xl, 12.3xq, 12.3xr, 12.3xu, 12.3xw, 12.3xx, 12.3xy, 12.3xz, 12.3yf, 12.3yg, 12.3yk, 12.3ym, 12.3yq, 12.3ys, 12.3yt, 12.3yu, 12.3yx, 12.3yz, 12.3za, 12.4, 12.4gc, 12.4md, 12.4mda, 12.4mr, 12.4t, 12.4xa, 12.4xb, 12.4xd, 12.4xp, 12.4xr, 12.4xt, 12.4ya, 12.4yb, 12.4yd, 12.4ye, 12.4yg |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
5.157%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cisco Systems, Inc. · Hosted Service · USA |
| Reserved | 2010-02-10T00:00:00 |
| Published | 2010-03-25T20:31:00 |
| Patch Date | 2010-03-24 |
| Last Updated | 2024-08-07T00:52:19 |
Community Chatter & Buzz