CVE-2009-5040 — Cisco IOS vulnerability
Severity
6.8MEDIUMNVD
EPSS
0.5%
top 33.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 7
Latest updateMay 2
Description
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.
CVSS vector
AV:N/AC:L/C:N/I:N/A:CExploitability: 8.0 | Impact: 6.9