CVE-2006-3594
published 2006-07-18CVE-2006-3594: Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.54%
88.0th percentile
Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP request, aka bug CSCsd96542.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
| cisco | unified_callmanager | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco Unified CallManager Vulnerabilities
vendor_cisco·2006-07-12·CVSS 10.0
CVE-2006-3592 [CRITICAL] CWE-119 Multiple Cisco Unified CallManager Vulnerabilities
Multiple Cisco Unified CallManager Vulnerabilities
Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI)
and Session Initiation Protocol (SIP) related vulnerabilities. There are
potential privilege escalation vulnerabilities in the CLI which may allow an
authenticated administrator to access the base operating system with root
privileges. There is also a buffer overflow vulnerability in the processing of
hostnames contained in a SIP request which may result in arbitrary code
execution or cause a denial of service. These vulnerabilities only affect Cisco
Unified CallManager 5.0.
Cisco has made free software available to address these vulnerabilities
for affected customers. There are no workarounds available to mitigate the
effects of these vulnerabilities.
This advisory i
Cisco
Multiple Cisco Unified CallManager Vulnerabilities
vendor_cisco
CVE-2006-3594 Multiple Cisco Unified CallManager Vulnerabilities
CVE-2006-3594: Multiple Cisco Unified CallManager Vulnerabilities
Cisco Unified CallManager (CUCM) 5.0 has Command Line Interface (CLI) and Session Initiation Protocol (SIP) related vulnerabilities. There are potential privilege escalation vulnerabilities in the CLI which may allow an authenticated administrator to access the base operating system with root privileges. There is also a buffer overflow vulnerability in the processing of hostnames contained in a SIP request which may result in arbitrary code execution or cause a denial of service. These vulnerabilities only affect Cisco Unified CallManager 5.0. Cisco has made free software available to address these vulnerabilities for affected customers. There are no
CWE: CWE-119, CWE-94, CWE-119, CWE-94
Bug IDs: CSCse11005, CSCse31704, CSCs
GHSA
GHSA-g2w2-69h2-v3w8: Buffer overflow in Cisco Unified CallManager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2006-3594 [HIGH] GHSA-g2w2-69h2-v3w8: Buffer overflow in Cisco Unified CallManager (CUCM) 5
Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP request, aka bug CSCsd96542.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/21030http://securitytracker.com/id?1016475http://www.cisco.com/warp/public/707/cisco-sa-20060712-cucm.shtmlhttp://www.osvdb.org/27162http://www.securityfocus.com/bid/18952http://www.vupen.com/english/advisories/2006/2774https://exchange.xforce.ibmcloud.com/vulnerabilities/27691http://secunia.com/advisories/21030http://securitytracker.com/id?1016475http://www.cisco.com/warp/public/707/cisco-sa-20060712-cucm.shtmlhttp://www.osvdb.org/27162http://www.securityfocus.com/bid/18952http://www.vupen.com/english/advisories/2006/2774https://exchange.xforce.ibmcloud.com/vulnerabilities/27691
2006-07-18
Published