CVE-2012-3935: Cisco Jabber Extensible Communications Platform

High severity, CVSS 7.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause a denial of service (process crash) via a crafted XMPP stream header, aka Bug ID CSCtu32832.

Affected products

  • Cisco Jabber Extensible Communications Platform: up to and including 5.2
  • Cisco Unified Presence: up to and including 8.6\(2\); version 1.0 only; version 6.0 only; version 6.0(1) only; version 6.0(2) only; version 6.0(3) only; …

Published 2012-09-12. Last modified 2026-06-16.