Vulnerability CVE-2005-4794


Published: 2005-12-31   Modified: 2012-02-12

Description:
Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset.

Vendor: Cisco
Product: ATA 
Version: 188; 186;
Product: Ip phone 7905 
Product: Application and content networking software 
Product: Unity express 
Product: Ip phone 7902 
Product: Ip phone 7912 
Product: Subscriber edge services manager 

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

 References:
http://securitytracker.com/id?1014043
http://securitytracker.com/id?1014044
http://securitytracker.com/id?1014045
http://securitytracker.com/id?1014046
http://securitytracker.com/id?1015975
http://www.cisco.com/warp/public/707/cisco-sn-20050524-dns.shtml
http://www.niscc.gov.uk/niscc/docs/al-20050524-00433.html
http://www.niscc.gov.uk/niscc/docs/re-20050524-00432.pdf?lang=en
http://www.securityfocus.com/bid/13729
https://exchange.xforce.ibmcloud.com/vulnerabilities/20712

Related CVE
CVE-2019-1899
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorizatio...
CVE-2019-1898
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of a...
CVE-2019-1897
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affected router. The vulnerability i...
CVE-2019-1875
A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to i...
CVE-2019-1874
A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to ins...
CVE-2019-1632
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected dev...
CVE-2019-1631
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to access potentially sensitive system usage information. The vulnerability is due to a lack of prop...
CVE-2019-1630
A vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer overflow, resulting in a denial of service (DoS) condition. The vulnerability is...

Copyright 2019, cxsecurity.com

 

Back to Top