CVE-2009-5040: Medium severity cisco ios vulnerability
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-5040?
CVE-2009-5040 is considered to have a medium severity due to its ability to cause a denial of service on affected Cisco IOS devices.
How do I fix CVE-2009-5040?
To fix CVE-2009-5040, upgrade to Cisco IOS version 15.0(1)XA or later, which includes a patch for this vulnerability.
What are the affected devices for CVE-2009-5040?
Devices running Cisco IOS versions prior to 15.0(1)XA that support CallManager Express and extension mobility are affected by CVE-2009-5040.
What types of attacks can CVE-2009-5040 be exploited for?
CVE-2009-5040 can be exploited by remote authenticated users to crash the device through specific interactions with the extension mobility menu.
Has CVE-2009-5040 been addressed in Cisco advisories?
Yes, CVE-2009-5040 has been documented and addressed in Cisco security advisories, encouraging users to apply the necessary updates.