CVE-2009-2865

critical

Description

Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/53448

http://www.vupen.com/english/advisories/2009/2758

http://www.securitytracker.com/id?1022932

http://www.securityfocus.com/bid/36498

http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8116.shtml

http://tools.cisco.com/security/center/viewAlert.x?alertId=18884

http://osvdb.org/58335

Details

Source: Mitre, NVD

Published: 2009-09-28

Updated: 2017-08-17

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical