6.8

CVE-2012-5445

The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Unified Ip Phone Version 7906g
Cisco ≫ Unified Ip Phone Version 7911g
Cisco ≫ Unified Ip Phone Version 7935
Cisco ≫ Unified Ip Phone Version 7936
Cisco ≫ Unified Ip Phone Version 7940
Cisco ≫ Unified Ip Phone Version 7940g
Cisco ≫ Unified Ip Phone Version 7941g
Cisco ≫ Unified Ip Phone Version 7960
Cisco ≫ Unified Ip Phone Version 7960g
Cisco ≫ Unified Ip Phone Version 7961g
Cisco ≫ Unified Ip Phone Version 7970g
Cisco ≫ Unified Ip Phone Version 7971g
Cisco ≫ Unified Ip Phone 7906g Version 7911g
Cisco ≫ Unified Ip Phone 7906g Version 7941g
Cisco ≫ Unified Ip Phone 7906g Version 7961g
Cisco ≫ Unified Ip Phone 7906g Version 7970g
Cisco ≫ Unified Ip Phone 7906g Version 7971g
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.316
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 3.1 10
AV:L/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://events.ccc.de/congress/2012/Fahrplan/events/5400.en.html
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130109-uipphone