Vulnerability Description
The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Skinny Client Control Protocol Software | <= 9.2\(4\) |
| Cisco | Unified Ip Phone | 7906g |
| Cisco | Unified Ip Phone 7906G | 7911g |
Related Weaknesses (CWE)
References
- http://events.ccc.de/congress/2012/Fahrplan/events/5400.en.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20
- http://events.ccc.de/congress/2012/Fahrplan/events/5400.en.html
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20
FAQ
What is CVE-2012-5445?
CVE-2012-5445 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows a...
How severe is CVE-2012-5445?
CVE-2012-5445 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-5445?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Skinny Client Control Protocol Software, Cisco Unified Ip Phone, Cisco Unified Ip Phone 7906G.