SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-0027

Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote…

HIGH 10.0EPSS 57.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 57.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
57.11% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
cisco/unified callmanager · cisco/unified communications manager
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.