Lucene search

K
cveCiscoCVE-2009-2865
HistorySep 28, 2009 - 7:30 p.m.

CVE-2009-2865

2009-09-2819:30:01
CWE-119
cisco
web.nvd.nist.gov
30
cisco
buffer overflow
extension mobility
cisco ios 12.4x
cve-2009-2865
nvd

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.031

Percentile

91.0%

Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.

Affected configurations

Nvd
Node
ciscounified_communications_manager_express
AND
ciscoiosMatch12.4xw
OR
ciscoiosMatch12.4xy
OR
ciscoiosMatch12.4xz
OR
ciscoiosMatch12.4ya
VendorProductVersionCPE
ciscounified_communications_manager_express*cpe:2.3:a:cisco:unified_communications_manager_express:*:*:*:*:*:*:*:*
ciscoios12.4xwcpe:2.3:o:cisco:ios:12.4xw:*:*:*:*:*:*:*
ciscoios12.4xycpe:2.3:o:cisco:ios:12.4xy:*:*:*:*:*:*:*
ciscoios12.4xzcpe:2.3:o:cisco:ios:12.4xz:*:*:*:*:*:*:*
ciscoios12.4yacpe:2.3:o:cisco:ios:12.4ya:*:*:*:*:*:*:*

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.031

Percentile

91.0%