Stack-Based Buffer Overflow in Cisco Intelligent Contact Manager Prior to Version 7.0
CVE-2010-3040

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
9 November 2010

Summary

Multiple stack-based buffer overflow vulnerabilities exist in the agent.exe component of the Setup Manager in Cisco Intelligent Contact Manager (ICM) prior to version 7.0. These vulnerabilities allow remote attackers to execute arbitrary code by sending specially crafted TCP packets with overly long parameters. The impacted functions include HandleUpgradeAll, AgentUpgrade, HandleQueryNodeInfoReq, and HandleUpgradeTrace, which may lead to system compromise if exploited.

References

EPSS Score

25% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.