CVE-2007-5538
published 2007-10-18CVE-2007-5538: Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and…
PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.53%
91.9th percentile
Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames, aka CSCsh47712.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_callmanager | — | — |
| cisco | unified_communications_manager | <= 5.1\(2\) | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco·2007-10-17·CVSS 10.0
CVE-2007-5537 [CRITICAL] CWE-119 Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly CallManager,
contains two denial of service (DoS) vulnerabilities. Large volumes of UDP
Session Initiation Protocol (SIP) INVITE messages may cause a resource
exhaustion condition on CUCM systems resulting in a kernel panic. The CUCM
Trivial File Transfer Protocol (TFTP) service contains a buffer overflow
vulnerability that may result in a denial of service condition or allow a
remote, unauthenticated user to execute arbitrary code. There are no
workarounds for these vulnerabilities.
Cisco has made free software available to address these vulnerabilities
for affected customers.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoS
Cisco
Cisco Unified Communications Manager Denial of Service Vulnerabilities
vendor_cisco
CVE-2007-5538 Cisco Unified Communications Manager Denial of Service Vulnerabilities
CVE-2007-5538: Cisco Unified Communications Manager Denial of Service Vulnerabilities
Cisco Unified Communications Manager (CUCM), formerly CallManager, contains two denial of service (DoS) vulnerabilities. Large volumes of UDP Session Initiation Protocol (SIP) INVITE messages may cause a resource exhaustion condition on CUCM systems resulting in a kernel panic. The CUCM Trivial File Transfer Protocol (TFTP) service contains a buffer overflow vulnerability that may result in a denial of service condition or allow a remote, unauthenticated user to execute arbitrary code. There are no
CWE: CWE-119, CWE-399, CWE-119, CWE-399
Bug IDs: CSCsi75822, CSCsh47712
GHSA
GHSA-76f8-93vw-4mch: Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5
ghsa_unreviewed·2022-05-01
CVE-2007-5538 [HIGH] CWE-119 GHSA-76f8-93vw-4mch: Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5
Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames, aka CSCsh47712.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/37940http://secunia.com/advisories/27296http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda34.shtmlhttp://www.securityfocus.com/bid/26105http://www.securitytracker.com/id?1018828http://www.vupen.com/english/advisories/2007/3532https://exchange.xforce.ibmcloud.com/vulnerabilities/37247http://osvdb.org/37940http://secunia.com/advisories/27296http://www.cisco.com/en/US/products/products_security_advisory09186a00808dda34.shtmlhttp://www.securityfocus.com/bid/26105http://www.securitytracker.com/id?1018828http://www.vupen.com/english/advisories/2007/3532https://exchange.xforce.ibmcloud.com/vulnerabilities/37247
2007-10-18
Published