Vulnerability Name:

CVE-2011-4487 (CCN-73556)

Assigned:2011-11-21
Published:2012-02-29
Updated:2012-03-05
Summary:SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a crafted SCCP registration, aka Bug ID CSCtu73538.
CVSS v3 Severity:6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-89
Vulnerability Consequences:Data Manipulation
References:Source: MITRE
Type: CNA
CVE-2011-4487

Source: CCN
Type: SA48218
Cisco Unified Communications Manager Denial of Service and SQL Injection Vulnerabilities

Source: CCN
Type: SA48231
Cisco Unified Communications Manager Denial of Service and SQL Injection Vulnerabilities

Source: CCN
Type: cisco-sa-20120229-cucm
Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities

Source: CISCO
Type: Vendor Advisory
20120229 Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities

Source: CCN
Type: OSVDB ID: 79706
Cisco Unified Communications Manager SCCP Registration Message SQL Injection

Source: CCN
Type: BID-52213
Cisco Unified Communications Manager SCCP (CVE-2011-4487) SQL Injection Vulnerability

Source: XF
Type: UNKNOWN
cucm-sccp-sql-injection(73556)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cisco:unified_communications_manager:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.0(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.0(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.0(1b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(1b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(2)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(2)su1a:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(3):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(3a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(3b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(3b)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(4):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(4)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(4a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(4a)su2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(5):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(5)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(5)su2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(5)su3:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:cisco:unified_communications_manager:7.0(1)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0(1)su1a:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0(2a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0(2a)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0(2a)su2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(2a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(2a)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(2b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(2b)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(3):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(3a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(3a)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(3a)su1a:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(3b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(3b)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(3b)su2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5)su1a:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5b)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5b)su1a:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5b)su2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5b)su3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1(5b)su4:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:cisco:unified_communications_manager:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(2a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(2b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(2c):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(2c)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(3):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(3a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(3a)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0(3a)su2:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:cisco:unified_communications_manager:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.5(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.5(1)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.5(1)su2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.5(1)su3:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/a:cisco:unified_communications_manager:8.6:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.6(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.6(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.6(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.6(2a):*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/a:cisco:business_edition_3000_software:8.6(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_3000_software:8.6(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_3000_software:8.6(2a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_3000_software:8.6.2:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:business_edition_3000:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/a:cisco:business_edition_5000_software:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_5000_software:8.5(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_5000_software:8.6:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_5000_software:8.6(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_5000_software:8.6(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_5000_software:8.6(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_5000_software:8.6(2a):*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:business_edition_5000:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/a:cisco:business_edition_6000_software:8.5(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.5(1)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.5(1)su2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.5(1)su3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.5(1-2011o):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.6(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.6(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.6(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:business_edition_6000_software:8.6(2a):*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:business_edition_6000:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:cisco:unified_communications_manager:6.0(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(1a):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.0(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(2)su1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0(1):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(1b):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:6.1(2)su1a:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.0(2):*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:7.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:unified_communications_manager:8.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco unified communications manager 6.0
    cisco unified communications manager 6.0(1)
    cisco unified communications manager 6.0(1a)
    cisco unified communications manager 6.0(1b)
    cisco unified communications manager 6.1(1)
    cisco unified communications manager 6.1(1a)
    cisco unified communications manager 6.1(1b)
    cisco unified communications manager 6.1(2)
    cisco unified communications manager 6.1(2)su1
    cisco unified communications manager 6.1(2)su1a
    cisco unified communications manager 6.1(3)
    cisco unified communications manager 6.1(3a)
    cisco unified communications manager 6.1(3b)
    cisco unified communications manager 6.1(3b)su1
    cisco unified communications manager 6.1(4)
    cisco unified communications manager 6.1(4)su1
    cisco unified communications manager 6.1(4a)
    cisco unified communications manager 6.1(4a)su2
    cisco unified communications manager 6.1(5)
    cisco unified communications manager 6.1(5)su1
    cisco unified communications manager 6.1(5)su2
    cisco unified communications manager 6.1(5)su3
    cisco unified communications manager 7.0(1)su1
    cisco unified communications manager 7.0(1)su1a
    cisco unified communications manager 7.0(2)
    cisco unified communications manager 7.0(2a)
    cisco unified communications manager 7.0(2a)su1
    cisco unified communications manager 7.0(2a)su2
    cisco unified communications manager 7.1(2a)
    cisco unified communications manager 7.1(2a)su1
    cisco unified communications manager 7.1(2b)
    cisco unified communications manager 7.1(2b)su1
    cisco unified communications manager 7.1(3)
    cisco unified communications manager 7.1(3a)
    cisco unified communications manager 7.1(3a)su1
    cisco unified communications manager 7.1(3a)su1a
    cisco unified communications manager 7.1(3b)
    cisco unified communications manager 7.1(3b)su1
    cisco unified communications manager 7.1(3b)su2
    cisco unified communications manager 7.1(5)
    cisco unified communications manager 7.1(5)su1
    cisco unified communications manager 7.1(5)su1a
    cisco unified communications manager 7.1(5a)
    cisco unified communications manager 7.1(5b)
    cisco unified communications manager 7.1(5b)su1
    cisco unified communications manager 7.1(5b)su1a
    cisco unified communications manager 7.1(5b)su2
    cisco unified communications manager 7.1(5b)su3
    cisco unified communications manager 7.1(5b)su4
    cisco unified communications manager 8.0
    cisco unified communications manager 8.0(1)
    cisco unified communications manager 8.0(2)
    cisco unified communications manager 8.0(2a)
    cisco unified communications manager 8.0(2b)
    cisco unified communications manager 8.0(2c)
    cisco unified communications manager 8.0(2c)su1
    cisco unified communications manager 8.0(3)
    cisco unified communications manager 8.0(3a)
    cisco unified communications manager 8.0(3a)su1
    cisco unified communications manager 8.0(3a)su2
    cisco unified communications manager 8.5
    cisco unified communications manager 8.5(1)
    cisco unified communications manager 8.5(1)su1
    cisco unified communications manager 8.5(1)su2
    cisco unified communications manager 8.5(1)su3
    cisco unified communications manager 8.6
    cisco unified communications manager 8.6(1)
    cisco unified communications manager 8.6(1a)
    cisco unified communications manager 8.6(2)
    cisco unified communications manager 8.6(2a)
    cisco business edition 3000 software 8.6(1)
    cisco business edition 3000 software 8.6(1a)
    cisco business edition 3000 software 8.6(2a)
    cisco business edition 3000 software 8.6.2
    cisco business edition 3000 -
    cisco business edition 5000 software 8.5
    cisco business edition 5000 software 8.5(1)
    cisco business edition 5000 software 8.6
    cisco business edition 5000 software 8.6(1)
    cisco business edition 5000 software 8.6(1a)
    cisco business edition 5000 software 8.6(2)
    cisco business edition 5000 software 8.6(2a)
    cisco business edition 5000 -
    cisco business edition 6000 software 8.5(1)
    cisco business edition 6000 software 8.5(1)su1
    cisco business edition 6000 software 8.5(1)su2
    cisco business edition 6000 software 8.5(1)su3
    cisco business edition 6000 software 8.5(1-2011o)
    cisco business edition 6000 software 8.6(1)
    cisco business edition 6000 software 8.6(1a)
    cisco business edition 6000 software 8.6(2)
    cisco business edition 6000 software 8.6(2a)
    cisco business edition 6000 -
    cisco unified communications manager 6.0(1a)
    cisco unified communications manager 6.0
    cisco unified communications manager 6.1(1a)
    cisco unified communications manager 6.1
    cisco unified communications manager 6.1(1)
    cisco unified communications manager 6.0(1)
    cisco unified communications manager 6.1(2)su1
    cisco unified communications manager 6.1(2)
    cisco unified communications manager 7.0
    cisco unified communications manager 6.1.0
    cisco unified communications manager 7.0(1)
    cisco unified communications manager 6.1(1b)
    cisco unified communications manager 6.1(2)su1a
    cisco unified communications manager 7.0(2)
    cisco unified communications manager 7.1
    cisco unified communications manager 8.0