CVE-2013-1220: Cisco Unified Customer Voice Portal

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148.

Affected products

  • Cisco Unified Customer Voice Portal: up to and including 9.0\(1\); version 3.0 only; version 3.6(10) only; version 4.0 only; version 4.0(2) only; version 4.1 only; …

Published 2013-05-09. Last modified 2026-06-16.