CVE-2017-6624: Medium severity Cisco IOS vulnerability
A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections component of the affected software. An attacker could exploit this vulnerability to place unauthorized, long-distance phone calls by using an affected system. Cisco Bug IDs: CSCuy40939.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6624?
CVE-2017-6624 has been identified with a high severity rating due to its potential to allow unauthorized phone calls.
How do I fix CVE-2017-6624?
To fix CVE-2017-6624, ensure you update to the latest version of Cisco IOS that addresses this vulnerability.
Who is affected by CVE-2017-6624?
CVE-2017-6624 affects users of Cisco IOS 15.5(3)M Software specifically used in Cisco CallManager Express.
What can an attacker do with CVE-2017-6624?
An attacker exploiting CVE-2017-6624 could make unauthorized phone calls due to insufficient toll-fraud protections.
Is CVE-2017-6624 an authenticated or unauthenticated vulnerability?
CVE-2017-6624 is an unauthenticated vulnerability, allowing remote attackers to exploit it without credentials.