CVE-2009-2865
Published Sep 28, 2009
Last updated 7 years ago
Overview
- Description
- Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
- Source
- ykramarz@cisco.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.6
- Impact score
- 10
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cisco:unified_communications_manager_express:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "720EB93A-AE27-470E-B8F8-45D1B6CBE94C" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:cisco:ios:12.4xw:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4362045B-7065-4FF9-A977-B3DA7894F831" }, { "criteria": "cpe:2.3:o:cisco:ios:12.4xy:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC27E79D-6B4B-4839-9664-DFE821C45C2E" }, { "criteria": "cpe:2.3:o:cisco:ios:12.4xz:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4963A243-74FA-43AD-9645-C9FAD527A6E1" }, { "criteria": "cpe:2.3:o:cisco:ios:12.4ya:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31C6EACA-35BE-4032-93DA-5F738AEE0F4A" } ], "operator": "OR" } ], "operator": "AND" } ]