Cisco Call Manager vulnerabilities
14 known vulnerabilities affecting cisco/call_manager.
Total CVEs
14
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM11
Vulnerabilities
Page 1 of 1
CVE-2007-5468MEDIUMCVSS 5.0v5.1.1.30002007-10-16
CVE-2007-5468 [MEDIUM] CWE-264 CVE-2007-5468: Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Requ
Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka "toll fraud and authentication forward attack").
nvd
CVE-2007-4634CRITICALCVSS 9.3PoCv3.3\(5\)sr1v3.3\(5\)sr2+14 more2007-08-31
CVE-2007-4634 [CRITICAL] CWE-89 CVE-2007-4634: Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM
Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.
nvd
CVE-2007-4633MEDIUMCVSS 4.3v3.3\(5\)sr1v3.3\(5\)sr2+15 more2007-08-31
CVE-2007-4633 [MEDIUM] CWE-79 CVE-2007-4633: Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications
Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.
nvd
CVE-2007-2832MEDIUMCVSS 4.3PoCv3.3v3.3\(3\)+17 more2007-05-24
CVE-2007-2832 [MEDIUM] CVE-2007-2832: Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before
Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allows remote attackers to inject arbitrary web script or HTML via the pattern parameter to CCMAdmin/serverlist.asp (aka the search-form) and possibly other unspecified vectors.
nvd
CVE-2006-3109MEDIUMCVSS 4.3PoCv3.3v3.3\(3\)+19 more2006-06-21
CVE-2006-3109 [MEDIUM] CVE-2006-3109: Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3
Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.
nvd
CVE-2006-0368HIGHCVSS 7.8v1.0v2.0+20 more2006-01-22
CVE-2006-0368 [HIGH] CVE-2006-0368: Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(
Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP c
nvd
CVE-2006-0367MEDIUMCVSS 6.5v1.0v2.0+16 more2006-01-22
CVE-2006-0367 [MEDIUM] CVE-2006-0367: Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0
Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."
nvd
CVE-2005-2243MEDIUMCVSS 5.0v3.2v3.3+2 more2005-07-12
CVE-2005-2243 [MEDIUM] CVE-2005-2243: Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 befor
Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) via a large number of Admin Service Tool (AST) logins that fail.
nvd
CVE-2005-2241MEDIUMCVSS 5.0v3.2v3.3+2 more2005-07-12
CVE-2005-2241 [MEDIUM] CVE-2005-2241: Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 befo
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe.
nvd
CVE-2005-2244MEDIUMCVSS 5.0v3.2v3.3+2 more2005-07-12
CVE-2005-2244 [MEDIUM] CVE-2005-2244: The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 b
The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.
nvd
CVE-2005-0356MEDIUMCVSS 5.0PoCv1.0v2.0+8 more2005-05-31
CVE-2005-0356 [MEDIUM] CVE-2005-0356: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timest
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
nvd
CVE-2004-1760CRITICALCVSS 10.0v1.0v2.0+8 more2004-01-21
CVE-2004-1760 [CRITICAL] CWE-287 CVE-2004-1760: The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
nvd
CVE-2004-1759MEDIUMCVSS 5.0v1.0v2.0+8 more2004-01-21
CVE-2004-1759 [MEDIUM] CWE-399 CVE-2004-1759: Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
nvd
CVE-2002-0505MEDIUMCVSS 5.0v3.0v3.12002-08-12
CVE-2002-0505 [MEDIUM] CVE-2002-0505: Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a denial of service (crash and reload) via a series of authentication failures, e.g. via incorrect passwords.
nvd