Vulnerability Description
Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than CVE-2006-4032. NOTE: the vendor, after working with the researcher, has been unable to reproduce the issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Pix Firewall 501 | All versions |
| Cisco | Pix Firewall 506 | All versions |
| Cisco | Pix Firewall 515 | All versions |
| Cisco | Pix Firewall 515E | All versions |
| Cisco | Pix Firewall 520 | All versions |
| Cisco | Pix Firewall 525 | All versions |
| Cisco | Pix Firewall 535 | All versions |
| Cisco | Pix Firewall Software | 6.3 |
References
- http://searchsecurity.techtarget.com/originalContent/0%2C289142%2Csid14_gci12074
- http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/tsd_products_security_resp
- http://www.idoel.smilejogja.com/2006/08/14/blinded-by-the-glare-of-facial-pierci
- http://www.networkworld.com/news/2006/080406-black-hat-unpatched-flaw-revealed.h
- http://www.osvdb.org/29781
- http://www.securityfocus.com/bid/19536
- http://searchsecurity.techtarget.com/originalContent/0%2C289142%2Csid14_gci12074
- http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/tsd_products_security_resp
- http://www.idoel.smilejogja.com/2006/08/14/blinded-by-the-glare-of-facial-pierci
- http://www.networkworld.com/news/2006/080406-black-hat-unpatched-flaw-revealed.h
- http://www.osvdb.org/29781
- http://www.securityfocus.com/bid/19536
FAQ
What is CVE-2006-4194?
CVE-2006-4194 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Pro...
How severe is CVE-2006-4194?
CVE-2006-4194 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-4194?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Pix Firewall 501, Cisco Pix Firewall 506, Cisco Pix Firewall 515, Cisco Pix Firewall 515E, Cisco Pix Firewall 520.