CVE-2007-4294
published 2007-08-09CVE-2007-4294: Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.55%
83.3th percentile
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_and_cisco_unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
vendor_cisco·2007-08-08·CVSS 10.0
CVE-2007-4291 [CRITICAL] CWE-399 Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
Multiple voice-related vulnerabilities are identified in Cisco IOS
software, one of which is also shared with Cisco Unified Communications
Manager. These vulnerabilities pertain to the following protocols or features:
Session Initiation Protocol (SIP)
Media Gateway Control Protocol (MGCP)
Signaling protocols H.323, H.254
Real-time Transport Protocol (RTP)
Facsimile reception
Cisco has made free software available to address these
vulnerabilities for affected customers. Fixed Cisco IOS software listed in the
Software Versions and Fixes section contains fixes for all
vulnerabilities mentioned in this advisory.
There are no workarounds available to mitigate the effects of any of
the vulnerabilities apart from
Cisco
Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
vendor_cisco
CVE-2007-4294 Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
CVE-2007-4294: Voice Vulnerabilities in Cisco IOS and Cisco Unified Communications Manager
Multiple voice-related vulnerabilities are identified in Cisco IOS software, one of which is also shared with Cisco Unified Communications Manager. These vulnerabilities pertain to the following protocols or features: Session Initiation Protocol (SIP) Media Gateway Control Protocol (MGCP) Signaling protocols H.323, H.254 Real-time Transport Protocol (RTP) Facsimile reception Cisco has made free software available to address these vulnerabilities for affected customers. Fixed Cisco IOS software listed in the Software Versions and Fixes section contains fixes for all vulnerabilities mentioned in this advisory. There are no
CWE: CWE-399, CWE-94, CWE-399, CWE-94
Bug IDs: CSCeb21064, CSCsb24007, CSCsc6024
GHSA
GHSA-jmjv-2hr3-5g9q: Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5
ghsa_unreviewed·2022-05-01
CVE-2007-4294 [MEDIUM] GHSA-jmjv-2hr3-5g9q: Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/36693http://secunia.com/advisories/26362http://securitytracker.com/id?1018538http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtmlhttp://www.securityfocus.com/bid/25239http://www.vupen.com/english/advisories/2007/2816https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5851http://osvdb.org/36693http://secunia.com/advisories/26362http://securitytracker.com/id?1018538http://www.cisco.com/en/US/products/products_security_advisory09186a0080899653.shtmlhttp://www.securityfocus.com/bid/25239http://www.vupen.com/english/advisories/2007/2816https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5851
2007-08-09
Published