CVE-2005-2244
Cisco CallManager <=3.2, 3.3<3.3(5), 4.0<4.0(2a)SR2b, 4.1<4.1(3)SR1 - RCE via Crafted Packets
Title source: llmDescription
The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19053
Patch, Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/14255
Scores
EPSS
0.0333
EPSS Percentile
87.3%
Details
Status
published
Products (4)
cisco/call_manager
3.2
cisco/call_manager
3.3
cisco/call_manager
4.0
cisco/call_manager
4.1
Published
Jul 12, 2005
Tracked Since
Feb 18, 2026