CVE-2011-4487
published 2012-03-01CVE-2011-4487: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6…
PriorityP340medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.03%
60.0th percentile
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a crafted SCCP registration, aka Bug ID CSCtu73538.
Affected
91 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_3000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_5000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | business_edition_6000_software | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
vendor_cisco·2012-03-01·CVSS 7.8
CVE-2011-4486 [HIGH] Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
Cisco Unified Communications Manager devices may allow a remote, unauthenticated attacker with the ability to send crafted Skinny Client Control Protocol (SCCP) messages to an affected device to cause a reload or execute attacker-controlled SQL code.
Cisco has released software updates that address these vulnerabilities.
Workarounds that mitigate these vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cucm
Cisco
Cisco Unified Communications Manager Device Registration SQL Injection Vulnerability
vendor_cisco·2012-02-29·CVSS 6.8
CVE-2011-4487 [MEDIUM] CWE-94 Cisco Unified Communications Manager Device Registration SQL Injection Vulnerability
Cisco Unified Communications Manager Device Registration SQL Injection Vulnerability
Cisco Unified Communications Manager contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands in a database underlying the affected application.
The vulnerability is due to improper sanitization of input in device registration requests. An unauthenticated, remote attacker could exploit this vulnerability by sending malicious requests to the targeted system. If successful, the attacker could modify application database contents.
Cisco has confirmed the vulnerability in a security advisory and released software updates.
To exploit the vulnerability, an attacker must be able to send device registration requests over the network to the targeted system. This
Cisco
Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
vendor_cisco
CVE-2011-4487 Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
CVE-2011-4487: Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
Cisco Unified Communications Manager devices may allow a remote, unauthenticated attacker with the ability to send crafted Skinny Client Control Protocol (SCCP) messages to an affected device to cause a reload or execute attacker-controlled SQL code. Cisco has released software updates that address these vulnerabilities.
Bug IDs: CSCtu73538, CSCtu73538, CSCtu73538
GHSA
GHSA-cvx2-r7fg-g587: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6
ghsa_unreviewed·2022-05-17
CVE-2011-4487 [MEDIUM] CWE-89 GHSA-cvx2-r7fg-g587: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a crafted SCCP registration, aka Bug ID CSCtu73538.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-03-01
Published