← Vulnerability feed

Vulnerability record · CVE-2008-3801 · published 26 September 2008

CVE-2008-3801: Cisco unified callmanager vulnerability

Cisco · Unified Callmanager

Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsm46064, a different vulnerability than CVE-2008-3800 and CVE-2008-3802.

7.1 CVSS 2.0 High EPSS 3.2% · top 12.2%
7.1CVSS 2.0 base score
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsm46064, a different vulnerability than CVE-2008-3800 and CVE-2008-3802.

AV:N/AC:M/Au:N/C:N/I:N/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/31990 Third Party Advisory
http://secunia.com/advisories/32013 Third Party Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a01562.shtml Vendor Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a0156a.shtml Vendor Advisory
http://www.securityfocus.com/bid/31367 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020939 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020942 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2008/2670 Permissions Required
http://www.vupen.com/english/advisories/2008/2671 Permissions Required
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6047 Third Party Advisory
http://secunia.com/advisories/31990 Third Party Advisory
http://secunia.com/advisories/32013 Third Party Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a01562.shtml Vendor Advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a0080a0156a.shtml Vendor Advisory
http://www.securityfocus.com/bid/31367 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020939 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1020942 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2008/2670 Permissions Required
http://www.vupen.com/english/advisories/2008/2671 Permissions Required
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6047 Third Party Advisory

Track CVE-2008-3801 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-20045Cisco Unified Communications products HTTP input code injection RCECisco Unified CM, Unified CM SME, IM & Presence, Unity Connection, and Webex Calling Dedicated Instance fail to properly validate user-supplied input…KEVEPSS 4.5%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6743Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that an authenticated, remote attacker can trigger with a crafted SNMP…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2008-3801), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.