VulnerabilityModified
CVE-2008-0529
Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.
HIGH 10.0EPSS 5.36%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.36% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- cisco/skinny client control protocol \(sccp\) firmware · cisco/session initiation protocol \(sip\) firmware
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/28935Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtmlPatch
- http://www.securityfocus.com/bid/27774
- http://www.securitytracker.com/id?1019410
- http://www.vupen.com/english/advisories/2008/0543
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40493
- http://secunia.com/advisories/28935Vendor Advisory
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtmlPatch
- http://www.securityfocus.com/bid/27774
- http://www.securitytracker.com/id?1019410
- http://www.vupen.com/english/advisories/2008/0543
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40493
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.