CVE-2010-0581

CRITICAL

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet ...

Affects 1 product across 1 vendor.

BCS7.77
CVSS 2.010.0
EPSS5.3%
Percentile92th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2010. A critical vulnerability affects Cisco systems (CVE-2010-0581). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2010-GLOBAL-084661-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2010-0581?
This vulnerability was disclosed in 2010. A critical vulnerability affects Cisco systems (CVE-2010-0581). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2010-0581?
CVE-2010-0581 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 5.3%.
Is CVE-2010-0581 actively exploited?
No confirmed active exploitation of CVE-2010-0581 as of 2026-09-25.
How do I remediate CVE-2010-0581?
Priority: MEDIUM. Advisory: http://tools.cisco.com/security/center/viewAlert.x?alertId=20065 PSIRT: [email protected]
What systems are affected by CVE-2010-0581?
CVE-2010-0581 affects: Cisco.
Vulnerability Details
CVE IDCVE-2010-0581
BSIDBS-2010-GLOBAL-084661-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2010-03-25
Last Modified2026-06-16
ICS Relevance55%
Domains
NETWORK-INFRA
SourceNVD
Official Description

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability." CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductAffected Versions
Cisco Ios 12.3jk 12.3t 12.3xd 12.3xf 12.3xg 12.3xi
+38 more12.3xj 12.3xk 12.3xl 12.3xq 12.3xr 12.3xu 12.3xw 12.3xx 12.3xy 12.3xz 12.3yf 12.3yg 12.3yk 12.3ym 12.3yq 12.3ys 12.3yt 12.3yu 12.3yx 12.3yz 12.3za 12.4 12.4gc 12.4md 12.4mda 12.4mr 12.4t 12.4xa 12.4xb 12.4xd 12.4xp 12.4xr 12.4xt 12.4ya 12.4yb 12.4yd 12.4ye 12.4yg
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 6033 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashd8164463f3bef190415780fd9322ec88a0a4223cea0c36a51aac84b4a0352a836c8a292bda5a56cd40afe6472d2d54491cc7b8cfc1b3ae4ac899d851983022b3
Related CVEs affecting Cisco
CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2009-4912 10.0 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software be... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un... CVE-2008-1157 10.0 Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process... CVE-2009-0617 10.0 Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL ro...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →