First published: Wed Aug 09 2006(Updated: )
Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4032 is classified as a high-severity vulnerability due to the potential exposure of sensitive information.
CVE-2006-4032 specifically affects Cisco CallManager Express version 3.0.
Remote attackers exploit CVE-2006-4032 by sending specific SIP messages to gain access to sensitive user information.
CVE-2006-4032 can lead to the compromise of sensitive information such as user names from the SIP user directory.
To mitigate the risk associated with CVE-2006-4032, it is recommended to update to the latest version of Cisco CallManager Express.