CVE-2006-4194
Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than…
Does this matter?
Lower severity and a low EPSS score (2.22%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than CVE-2006-4032. NOTE: the vendor, after working with the researcher, has been unable to reproduce the issue
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.22% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- cisco/pix firewall 501 · cisco/pix firewall 506 · cisco/pix firewall 515 · cisco/pix firewall 515e · cisco/pix firewall 520 · cisco/pix firewall 525 · cisco/pix firewall 535 · cisco/pix firewall software
- Source
- cve@mitre.org
References
- http://searchsecurity.techtarget.com/originalContent/0%2C289142%2Csid14_gci1207450%2C00.html
- http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/tsd_products_security_response09186a008070d33b.html
- http://www.idoel.smilejogja.com/2006/08/14/blinded-by-the-glare-of-facial-piercings-at-black-hat-or-the-one-that-got-away/
- http://www.networkworld.com/news/2006/080406-black-hat-unpatched-flaw-revealed.html?t5
- http://www.osvdb.org/29781
- http://www.securityfocus.com/bid/19536
- http://searchsecurity.techtarget.com/originalContent/0%2C289142%2Csid14_gci1207450%2C00.html
- http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/tsd_products_security_response09186a008070d33b.html
- http://www.idoel.smilejogja.com/2006/08/14/blinded-by-the-glare-of-facial-piercings-at-black-hat-or-the-one-that-got-away/
- http://www.networkworld.com/news/2006/080406-black-hat-unpatched-flaw-revealed.html?t5
- http://www.osvdb.org/29781
- http://www.securityfocus.com/bid/19536
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.