CVE-2005-2241
published 2005-07-12CVE-2005-2241: Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information…
PriorityP417medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.26%
66.1th percentile
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | call_manager | — | — |
| cisco | callmanager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco CallManager Memory Handling Vulnerabilities
vendor_cisco·2005-07-12
CVE-2005-2241 Cisco CallManager Memory Handling Vulnerabilities
Cisco CallManager Memory Handling Vulnerabilities
Cisco CallManager (CCM) is the software-based call-processing component
of the Cisco IP telephony solution which extends enterprise telephony features
and functions to packet telephony network devices such as IP phones, media
processing devices, voice-over-IP (VoIP) gateways, and multimedia applications.
Cisco CallManager 3.3 and earlier, 4.0, and 4.1 are vulnerable to Denial of
Service (DoS) attacks, memory leaks, and memory corruption which may result in
services being interrupted, servers rebooting, or arbitrary code being
executed.
Cisco has made free software available to address these
vulnerabilities.
This advisory will be posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20050712-ccm.
Cisco
Cisco CallManager Memory Handling Vulnerabilities
vendor_cisco
CVE-2005-2241 Cisco CallManager Memory Handling Vulnerabilities
CVE-2005-2241: Cisco CallManager Memory Handling Vulnerabilities
Cisco CallManager (CCM) is the software-based call-processing component of the Cisco IP telephony solution which extends enterprise telephony features and functions to packet telephony network devices such as IP phones, media processing devices, voice-over-IP (VoIP) gateways, and multimedia applications. Cisco CallManager 3.3 and earlier, 4.0, and 4.1 are vulnerable to Denial of Service (DoS) attacks, memory leaks, and memory corruption which may result in services being interrupted, servers rebooting, or arbitrary code being executed. Cisco has made free software available to address these vulnerabilities. This advisory will be posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2
GHSA
GHSA-p2fc-grwr-w3x3: Cisco CallManager (CCM) 3
ghsa_unreviewed·2022-05-01
CVE-2005-2241 [MEDIUM] GHSA-p2fc-grwr-w3x3: Cisco CallManager (CCM) 3
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.
No detection rules found.
No writeups or analysis indexed.
2005-07-12
Published