Lucene search

K
nvd[email protected]NVD:CVE-2009-2865
HistorySep 28, 2009 - 7:30 p.m.

CVE-2009-2865

2009-09-2819:30:01
CWE-119
web.nvd.nist.gov
6

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.031

Percentile

91.0%

Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.

Affected configurations

Nvd
Node
ciscounified_communications_manager_express
AND
ciscoiosMatch12.4xw
OR
ciscoiosMatch12.4xy
OR
ciscoiosMatch12.4xz
OR
ciscoiosMatch12.4ya
VendorProductVersionCPE
ciscounified_communications_manager_express*cpe:2.3:a:cisco:unified_communications_manager_express:*:*:*:*:*:*:*:*
ciscoios12.4xwcpe:2.3:o:cisco:ios:12.4xw:*:*:*:*:*:*:*
ciscoios12.4xycpe:2.3:o:cisco:ios:12.4xy:*:*:*:*:*:*:*
ciscoios12.4xzcpe:2.3:o:cisco:ios:12.4xz:*:*:*:*:*:*:*
ciscoios12.4yacpe:2.3:o:cisco:ios:12.4ya:*:*:*:*:*:*:*

CVSS2

7.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0.031

Percentile

91.0%