CVE-2010-0581
published 2010-03-25CVE-2010-0581: Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message…
PriorityP350critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.10%
88.9th percentile
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6jpg-grj3-vm57: Unspecified vulnerability in the SIP implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2010-0581 [HIGH] GHSA-6jpg-grj3-vm57: Unspecified vulnerability in the SIP implementation in Cisco IOS 12
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco·2010-03-24·CVSS 10.0
CVE-2010-0579 [CRITICAL] CWE-399 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP)
implementation in Cisco IOS® Software that could
allow an unauthenticated, remote attacker to cause a reload of an affected
device when SIP operation is enabled. Remote code execution may also be
possible.
Cisco has released software updates that address these vulnerabilities. For devices that must run SIP there are no workarounds;
however, mitigations are available to limit exposure of the
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100324-sip.
Note: The March 24, 2010, Cisco IOS Software Security Advisory bundled
publication includes seven Securit
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco
CVE-2010-0581 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
CVE-2010-0581: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS ® Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device when SIP operation is enabled. Remote code execution may also be possible. Cisco has released software updates that address these vulnerabilities. For devices that must run SIP there are no
CWE: CWE-399, CWE-94, CWE-399, CWE-94
Bug IDs: CSCsz48680, CSCsz89904, CSCtb93416, CSCsz48680, CSCsz89904
No detection rules found.
Exploit-DB
CA BrightStor ARCserve License Service - 'GCR NETWORK' Remote Buffer Overflow (Metasploit)
exploitdb·2010-11-03
CVE-2005-0581 CA BrightStor ARCserve License Service - 'GCR NETWORK' Remote Buffer Overflow (Metasploit)
CA BrightStor ARCserve License Service - 'GCR NETWORK' Remote Buffer Overflow (Metasploit)
---
##
# $Id: license_gcr.rb 10892 2010-11-03 22:09:44Z mc $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'CA BrightStor ARCserve License Service GCR NETWORK Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in Computer Associates BrightStor ARCserve Backup 11.0.
By sending a specially crafted request to the lic98rmtd.exe service, an attacker
could overflow the buffer and execute arbitrary code.
},
'Author' => [ 'MC
Exploit-DB
Computer Associates License Client - GETCONFIG Overflow (Metasploit)
exploitdb·2010-09-20
CVE-2005-0581 Computer Associates License Client - GETCONFIG Overflow (Metasploit)
Computer Associates License Client - GETCONFIG Overflow (Metasploit)
---
##
# $Id: calicclnt_getconfig.rb 10394 2010-09-20 08:06:27Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Computer Associates License Client GETCONFIG Overflow',
'Description' => %q{
This module exploits an vulnerability in the CA License Client
service. This exploit will only work if your IP address can be
resolved from the target system point of view. This can be
accomplished on a local network by running the 'nmbd' service
that comes with Samba. If you are
Exploit-DB
Computer Associates License Server - GETCONFIG Overflow (Metasploit)
exploitdb·2010-09-20
CVE-2005-0581 Computer Associates License Server - GETCONFIG Overflow (Metasploit)
Computer Associates License Server - GETCONFIG Overflow (Metasploit)
---
##
# $Id: calicserv_getconfig.rb 10394 2010-09-20 08:06:27Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Computer Associates License Server GETCONFIG Overflow',
'Description' => %q{
This module exploits an vulnerability in the CA License Server
network service. By sending an excessively long GETCONFIG
packet the stack may be overwritten.
},
'Author' =>
[
'Thor Doomen ', # original msf v2 module
'patrick', # msf v3 port :)
],
'License' => MSF_LICENSE,
'Versio
http://secunia.com/advisories/39068http://securitytracker.com/id?1023744http://tools.cisco.com/security/center/viewAlert.x?alertId=20065http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtmlhttp://secunia.com/advisories/39068http://securitytracker.com/id?1023744http://tools.cisco.com/security/center/viewAlert.x?alertId=20065http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml
2010-03-25
Published