CVE-2002-0505
published 2002-08-12CVE-2002-0505: Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.77%
75.5th percentile
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
LDAP Connection Leak in CTI when User Authentication Fails
vendor_cisco·2002-03-27
CVE-2002-0505 CWE-399 LDAP Connection Leak in CTI when User Authentication Fails
LDAP Connection Leak in CTI when User Authentication Fails
The Cisco CallManager, running certain software releases, has a
vulnerability wherein a memory leak in the CTI Framework authentication can
cause the server to crash and result in a reload. This vulnerability can be
exploited to initiate a denial of service (DoS) attack.
This vulnerability is documented as Cisco bug ID CSCdv28302. There are
workarounds available to mitigate the vulnerability.
This advisory is available at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020327-cm-ctifw-leak.
Cisco
LDAP Connection Leak in CTI when User Authentication Fails
vendor_cisco
CVE-2002-0505 LDAP Connection Leak in CTI when User Authentication Fails
CVE-2002-0505: LDAP Connection Leak in CTI when User Authentication Fails
The Cisco CallManager, running certain software releases, has a vulnerability wherein a memory leak in the CTI Framework authentication can cause the server to crash and result in a reload. This vulnerability can be exploited to initiate a denial of service (DoS) attack. This vulnerability is documented as Cisco bug ID CSCdv28302. There are
CWE: CWE-399, CWE-399
Bug IDs: CSCdv28302, CSCdv28302, CSCdv28302
GHSA
GHSA-vwq6-34g6-9p39: Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3
ghsa_unreviewed·2022-04-30
CVE-2002-0505 [MEDIUM] GHSA-vwq6-34g6-9p39: Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/warp/public/707/callmanager-ctifw-leak-pub.shtmlhttp://www.iss.net/security_center/static/8655.phphttp://www.securityfocus.com/bid/4370http://www.cisco.com/warp/public/707/callmanager-ctifw-leak-pub.shtmlhttp://www.iss.net/security_center/static/8655.phphttp://www.securityfocus.com/bid/4370
2002-08-12
Published