9.3

CVE-2006-5277

Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
CiscoUnified Callmanager Version >= 3.3 <= 3.3\(5\)sr2
CiscoUnified Callmanager Version >= 4.1 <= 4.1\(3\)sr4
CiscoUnified Callmanager Version >= 4.2 <= 4.2\(3\)sr1
CiscoUnified Callmanager Version5.0
CiscoUnified Communications Manager Version >= 4.3 <= 4.3\(1\)
CiscoUnified Communications Manager Version >= 5.1 <= 5.1\(1\)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.46% 0.892
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C