CVE-2005-2244

Cisco CallManager <=3.2, 3.3<3.3(5), 4.0<4.0(2a)SR2b, 4.1<4.1(3)SR1 - RCE via Crafted Packets

Title source: llm
STIX 2.1

Description

The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19053
Patch, Vendor Advisory vendor-advisory x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14255

Scores

EPSS 0.0333
EPSS Percentile 87.3%

Details

Status published
Products (4)
cisco/call_manager 3.2
cisco/call_manager 3.3
cisco/call_manager 4.0
cisco/call_manager 4.1
Published Jul 12, 2005
Tracked Since Feb 18, 2026