CVE-2006-5278

UnknownEPSS 8.88%

Last modified

CVE-2006-5278 is a vulnerability of currently unknown severity. Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.. EPSS estimates a 8.88% chance of exploitation in the next 30 days.

Description

Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.

Metrics

EPSS Probability
8.88%

94.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CiscoUnified Callmanager>= 3.3, <= 3.3\(5\)sr2
CiscoUnified Callmanager>= 4.1, <= 4.1\(3\)sr4
CiscoUnified Callmanager>= 4.2, <= 4.2\(3\)sr1
CiscoUnified Callmanager>= 5.1, <= 5.1\(2\)
CiscoUnified Callmanager5.0
CiscoUnified Communications Manager>= 4.3, <= 4.3\(1\)

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2006-5278?
Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.
How severe is CVE-2006-5278?
Severity scoring for CVE-2006-5278 is pending analysis. The EPSS model estimates a 8.88% probability of exploitation in the next 30 days.
How do I fix CVE-2006-5278?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2006-5278?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST