CVE-2011-4486
published 2012-03-01CVE-2011-4486: Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco…
PriorityP336high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.31%
67.5th percentile
Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allow remote attackers to cause a denial of service (device reload) via a crafted SCCP registration, aka Bug ID CSCtu73538.
Affected
91 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
vendor_cisco·2012-03-01·CVSS 7.8
CVE-2011-4486 [HIGH] Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
Cisco Unified Communications Manager devices may allow a remote, unauthenticated attacker with the ability to send crafted Skinny Client Control Protocol (SCCP) messages to an affected device to cause a reload or execute attacker-controlled SQL code.
Cisco has released software updates that address these vulnerabilities.
Workarounds that mitigate these vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cucm
Cisco
Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
vendor_cisco
CVE-2011-4486 Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
CVE-2011-4486: Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
Cisco Unified Communications Manager devices may allow a remote, unauthenticated attacker with the ability to send crafted Skinny Client Control Protocol (SCCP) messages to an affected device to cause a reload or execute attacker-controlled SQL code. Cisco has released software updates that address these vulnerabilities.
Bug IDs: CSCtu73538, CSCtu73538, CSCtu73538
GHSA
GHSA-7gpg-mpjm-jm5f: Cisco Unified Communications Manager (CUCM) with software 6
ghsa_unreviewed·2022-05-17
CVE-2011-4486 [HIGH] GHSA-7gpg-mpjm-jm5f: Cisco Unified Communications Manager (CUCM) with software 6
Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allow remote attackers to cause a denial of service (device reload) via a crafted SCCP registration, aka Bug ID CSCtu73538.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-03-01
Published