Description
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."
CVSS vector
AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0 Affected Packages1 packages
🔴Vulnerability Details
2GHSAGHSA-6jpg-grj3-vm57: Unspecified vulnerability in the SIP implementation in Cisco IOS 12↗2022-05-02 ▶ CVEListCVE-2010-0581: Unspecified vulnerability in the SIP implementation in Cisco IOS 12↗2010-03-25 ▶ 💥Exploits & PoCs
3Exploit-DBCA BrightStor ARCserve License Service - 'GCR NETWORK' Remote Buffer Overflow (Metasploit)↗2010-11-03 ▶ Exploit-DBComputer Associates License Client - GETCONFIG Overflow (Metasploit)↗2010-09-20 ▶ Exploit-DBComputer Associates License Server - GETCONFIG Overflow (Metasploit)↗2010-09-20 ▶ 📋Vendor Advisories
1CiscoCisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities↗2010-03-24 ▶ 📄Research Papers
1arXivFormal Black-Box Analysis of Routing Protocol Implementations↗2017-09-23 ▶