6.8

CVE-2012-5445

The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.

Data is provided by the National Vulnerability Database (NVD)
CiscoUnified Ip Phone Version7906g
CiscoUnified Ip Phone Version7911g
CiscoUnified Ip Phone Version7935
CiscoUnified Ip Phone Version7936
CiscoUnified Ip Phone Version7940
CiscoUnified Ip Phone Version7940g
CiscoUnified Ip Phone Version7941g
CiscoUnified Ip Phone Version7960
CiscoUnified Ip Phone Version7960g
CiscoUnified Ip Phone Version7961g
CiscoUnified Ip Phone Version7970g
CiscoUnified Ip Phone Version7971g
CiscoUnified Ip Phone 7906g Version7911g
CiscoUnified Ip Phone 7906g Version7941g
CiscoUnified Ip Phone 7906g Version7961g
CiscoUnified Ip Phone 7906g Version7970g
CiscoUnified Ip Phone 7906g Version7971g
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.574
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 3.1 10
AV:L/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.