Vulnerability Name: CVE-2006-5553 (CCN-29829) Assigned: 2006-10-25 Published: 2006-10-25 Updated: 2017-07-20 Summary: Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certain options. This vulnerability is addressed in the following product updates:
Cisco, Unified CallManager, 5.0(4)
Cisco, Unified CallManager, 5.0(4a) with CSA COP upgrade
Cisco, Unified Presence Server, 1.0(2) with CSA COP upgrade
Cisco, Security Agent, 5.0.193
Cisco, Security Agent, 4.5.1.657
Cisco, Security Agent, 5.1 CVSS v3 Severity: 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): High
CVSS v2 Severity: 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
Vulnerability Type: CWE-Other Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2006-5553 Source: CCN Type: SA22574Cisco Security Agent for Linux Port Scan Denial of Service Source: SECUNIA Type: UNKNOWN22574 Source: CCN Type: SECTRACK ID: 1017118Cisco Security Agent for Linux Lets Remote Users Deny Service By Conducting Port Scans Source: SECTRACK Type: UNKNOWN1017118 Source: CISCO Type: Patch, Vendor Advisory20061025 Cisco Security Agent for Linux Port Scan Denial of Service Source: CCN Type: cisco-sa-20061025-csaCisco Security Advisory: Cisco Security Agent for Linux Port Scan Denial of Service Source: OSVDB Type: UNKNOWN30055 Source: CCN Type: OSVDB ID: 30055Cisco Security Agent for Linux Port Scan DoS Source: BID Type: Patch20737 Source: CCN Type: BID-20737Cisco Security Agent Remote Port Scan Denial of Service Vulnerability Source: VUPEN Type: UNKNOWNADV-2006-4198 Source: XF Type: UNKNOWNcsa-port-scan-dos(29829) Source: XF Type: UNKNOWNcsa-port-scan-dos(29829) Vulnerable Configuration: Configuration 1 :cpe:/a:cisco:security_agent:4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:security_agent:4.5.1:*:*:*:*:*:*:* OR cpe:/a:cisco:security_agent:4.5.1.639:*:*:*:*:*:*:* OR cpe:/a:cisco:security_agent:5.0:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(2):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(3):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(3a):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(4):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_presence_server:1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_presence_server:1.0(2):*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:cisco:security_agent:4.5:*:*:*:*:*:*:* OR cpe:/a:cisco:security_agent:4.5.1:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(1):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(2):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(3):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(3a):*:*:*:*:*:*:* OR cpe:/a:cisco:security_agent:5.0:*:*:*:*:*:*:* OR cpe:/a:cisco:security_agent:4.5.1.639:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_callmanager:5.0(4):*:*:*:*:*:*:* OR cpe:/a:cisco:unified_presence_server:1.0:*:*:*:*:*:*:* OR cpe:/a:cisco:unified_presence_server:1.0(2):*:*:*:*:*:*:* Denotes that component is vulnerable BACK
cisco security agent 4.5
cisco security agent 4.5.1
cisco security agent 4.5.1.639
cisco security agent 5.0
cisco unified callmanager 5.0(1)
cisco unified callmanager 5.0(2)
cisco unified callmanager 5.0(3)
cisco unified callmanager 5.0(3a)
cisco unified callmanager 5.0(4)
cisco unified presence server 1.0
cisco unified presence server 1.0(2)
cisco security agent 4.5
cisco security agent 4.5.1
cisco unified callmanager 5.0(1)
cisco unified callmanager 5.0(2)
cisco unified callmanager 5.0(3)
cisco unified callmanager 5.0(3a)
cisco security agent 5.0
cisco security agent 4.5.1.639
cisco unified callmanager 5.0(4)
cisco unified presence server 1.0
cisco unified presence server 1.0(2)