CVE-2009-5040Cisco IOS vulnerability

CWE-3993 documents3 sources
Severity
6.8MEDIUMNVD
EPSS
0.5%
top 33.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 7
Latest updateMay 2

Description

CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 8.0 | Impact: 6.9

Affected Packages1 packages

NVDcisco/ios15.0xa+1549

🔴Vulnerability Details

2
GHSA
GHSA-xjq5-7h7q-37wc: CallManager Express (CME) on Cisco IOS before 152022-05-02
CVEList
CVE-2009-5040: CallManager Express (CME) on Cisco IOS before 152011-01-07
CVE-2009-5040 — Cisco IOS vulnerability | cvebase