CVE-2007-5538

Severity
10.0CRITICAL
EPSS
7.5%
top 8.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 18
Latest updateMay 1

Description

Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames, aka CSCsh47712.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

šŸ”“Vulnerability Details

2
GHSA
GHSA-76f8-93vw-4mch: Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5↗2022-05-01
ā–¶
CVEList
CVE-2007-5538: Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5↗2007-10-18
ā–¶

šŸ“‹Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities↗2007-10-17
ā–¶
CVE-2007-5538 (CRITICAL CVSS 10) | Buffer overflow in the Centralized | cvebase.io