CVE-2006-3592
published 2006-07-18CVE-2006-3592: Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute…
PriorityP424medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.81%
52.8th percentile
Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute arbitrary commands with elevated privileges via unspecified vectors, involving "certain CLI commands," aka bug CSCse11005.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrm2-68wq-2hr3: Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2006-3592 [MEDIUM] GHSA-vrm2-68wq-2hr3: Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5
Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute arbitrary commands with elevated privileges via unspecified vectors, involving "certain CLI commands," aka bug CSCse11005.
Cisco
Multiple Cisco Unified CallManager Vulnerabilities
vendor_cisco·2006-07-12·CVSS 10.0
CVE-2006-3592 [CRITICAL] CWE-119 Multiple Cisco Unified CallManager Vulnerabilities
Multiple Cisco Unified CallManager Vulnerabilities
Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI)
and Session Initiation Protocol (SIP) related vulnerabilities. There are
potential privilege escalation vulnerabilities in the CLI which may allow an
authenticated administrator to access the base operating system with root
privileges. There is also a buffer overflow vulnerability in the processing of
hostnames contained in a SIP request which may result in arbitrary code
execution or cause a denial of service. These vulnerabilities only affect Cisco
Unified CallManager 5.0.
Cisco has made free software available to address these vulnerabilities
for affected customers. There are no workarounds available to mitigate the
effects of these vulnerabilities.
This advisory i
Cisco
Multiple Cisco Unified CallManager Vulnerabilities
vendor_cisco
CVE-2006-3592 Multiple Cisco Unified CallManager Vulnerabilities
CVE-2006-3592: Multiple Cisco Unified CallManager Vulnerabilities
Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI) and Session Initiation Protocol (SIP) related vulnerabilities. There are potential privilege escalation vulnerabilities in the CLI which may allow an authenticated administrator to access the base operating system with root privileges. There is also a buffer overflow vulnerability in the processing of hostnames contained in a SIP request which may result in arbitrary code execution or cause a denial of service. These vulnerabilities only affect Cisco Unified CallManager 5.0. Cisco has made free software available to address these vulnerabilities for affected customers. There are no
CWE: CWE-119, CWE-94, CWE-119, CWE-94
Bug IDs: CSCse11005, CSCse31704, CSCs
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/21030http://securitytracker.com/id?1016475http://www.cisco.com/warp/public/707/cisco-sa-20060712-cucm.shtmlhttp://www.osvdb.org/27160http://www.securityfocus.com/bid/18952http://www.vupen.com/english/advisories/2006/2774https://exchange.xforce.ibmcloud.com/vulnerabilities/27689http://secunia.com/advisories/21030http://securitytracker.com/id?1016475http://www.cisco.com/warp/public/707/cisco-sa-20060712-cucm.shtmlhttp://www.osvdb.org/27160http://www.securityfocus.com/bid/18952http://www.vupen.com/english/advisories/2006/2774https://exchange.xforce.ibmcloud.com/vulnerabilities/27689
2006-07-18
Published