Heap-based Buffer Overflow Vulnerability in Cisco Unified Communications Manager
CVE-2006-5277

Currently unrated

What is CVE-2006-5277?

An off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) of Cisco Unified Communications Manager prior to version 20070711 can be exploited by remote attackers. By sending a specially crafted packet, an attacker may trigger a heap-based buffer overflow, potentially allowing them to execute arbitrary code on the affected system. This vulnerability places users at risk and underscores the importance of keeping software updated.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.