CVE-2006-3593
published 2006-07-18CVE-2006-3593: The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
0.99%
58.7th percentile
The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v3vp-hcc4-xxfh: The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2006-3593 [MEDIUM] GHSA-v3vp-hcc4-xxfh: The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5
The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704.
Cisco
Multiple Cisco Unified CallManager Vulnerabilities
vendor_cisco·2006-07-12·CVSS 10.0
CVE-2006-3592 [CRITICAL] CWE-119 Multiple Cisco Unified CallManager Vulnerabilities
Multiple Cisco Unified CallManager Vulnerabilities
Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI)
and Session Initiation Protocol (SIP) related vulnerabilities. There are
potential privilege escalation vulnerabilities in the CLI which may allow an
authenticated administrator to access the base operating system with root
privileges. There is also a buffer overflow vulnerability in the processing of
hostnames contained in a SIP request which may result in arbitrary code
execution or cause a denial of service. These vulnerabilities only affect Cisco
Unified CallManager 5.0.
Cisco has made free software available to address these vulnerabilities
for affected customers. There are no workarounds available to mitigate the
effects of these vulnerabilities.
This advisory i
Cisco
Multiple Cisco Unified CallManager Vulnerabilities
vendor_cisco
CVE-2006-3593 Multiple Cisco Unified CallManager Vulnerabilities
CVE-2006-3593: Multiple Cisco Unified CallManager Vulnerabilities
Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI) and Session Initiation Protocol (SIP) related vulnerabilities. There are potential privilege escalation vulnerabilities in the CLI which may allow an authenticated administrator to access the base operating system with root privileges. There is also a buffer overflow vulnerability in the processing of hostnames contained in a SIP request which may result in arbitrary code execution or cause a denial of service. These vulnerabilities only affect Cisco Unified CallManager 5.0. Cisco has made free software available to address these vulnerabilities for affected customers. There are no
CWE: CWE-119, CWE-94, CWE-119, CWE-94
Bug IDs: CSCse11005, CSCse31704, CSCs
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/21030http://securitytracker.com/id?1016475http://www.cisco.com/en/US/products/products_security_advisory09186a00806e0b9f.shtmlhttp://www.osvdb.org/27161http://www.securityfocus.com/bid/18952http://www.vupen.com/english/advisories/2006/2774https://exchange.xforce.ibmcloud.com/vulnerabilities/27690http://secunia.com/advisories/21030http://securitytracker.com/id?1016475http://www.cisco.com/en/US/products/products_security_advisory09186a00806e0b9f.shtmlhttp://www.osvdb.org/27161http://www.securityfocus.com/bid/18952http://www.vupen.com/english/advisories/2006/2774https://exchange.xforce.ibmcloud.com/vulnerabilities/27690
2006-07-18
Published