Heap-based Buffer Overflow Vulnerability in Cisco Unified Communications Manager
CVE-2006-5277
Currently unrated
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 15 July 2007
Summary
An off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) of Cisco Unified Communications Manager prior to version 20070711 can be exploited by remote attackers. By sending a specially crafted packet, an attacker may trigger a heap-based buffer overflow, potentially allowing them to execute arbitrary code on the affected system. This vulnerability places users at risk and underscores the importance of keeping software updated.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved