Vulnerability Name: | CVE-2005-2243 (CCN-21326) | ||||||||
Assigned: | 2005-07-12 | ||||||||
Published: | 2005-07-12 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) via a large number of Admin Service Tool (AST) logins that fail. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Jul 19 2005 - 21:03:36 CDT PatchAdvisor Vulnerability Alert - Cisco CallManager Remote Denial of Service Vulnerability Source: MITRE Type: CNA CVE-2005-2243 Source: CCN Type: Cisco CallManager Web page Introduction Source: CCN Type: Cisco Security Advisory 2005 July 12 1500 UTC (GMT) Cisco CallManager Memory Handling Vulnerabilities Source: CISCO Type: Patch, Vendor Advisory 20050712 Cisco CallManager Memory Handling Vulnerabilities Source: CCN Type: OSVDB ID: 17848 Cisco CallManager MLA Failed Login Saturation DoS Source: BID Type: UNKNOWN 14253 Source: CCN Type: BID-14253 Cisco CallManager Multiple Failed Logins Remote Denial Of Service Vulnerability Source: CCN Type: BID-14255 Cisco CallManager AUPair Service Remote Heap Buffer Overflow Vulnerability Source: CCN Type: BID-16295 Cisco CallManager Multiple Remote Denial Of Service Vulnerabilities Source: XF Type: UNKNOWN cisco-callmanager-mla-dos(21326) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |