First published: Mon Sep 28 2009(Updated: )
Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco CallManager Express | ||
Cisco IOS | =12.4xw | |
Cisco IOS | =12.4xy | |
Cisco IOS | =12.4xz | |
Cisco IOS | =12.4ya |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2865 is rated as a high-severity vulnerability due to its potential for remote code execution and denial of service.
To fix CVE-2009-2865, upgrade to a version of Cisco IOS that is not vulnerable, specifically versions later than 12.4YA.
CVE-2009-2865 affects Cisco Unified Communications Manager Express and Cisco IOS versions 12.4XW, 12.4XY, 12.4XZ, and 12.4YA.
CVE-2009-2865 can be exploited through crafted HTTP requests that trigger a buffer overflow.
CVE-2009-2865 is a remote vulnerability, allowing attackers to execute code without physical access to the device.