CVE-2009-2865

high Cisco
CVSS v3 Base Score
7.6
AV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS Score
3.7%
Exploitation probability in 30 days
Top 12% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Confidentiality
C
Integrity
C
Availability
C
Published: September 28, 2009 (6071 days ago)
Last Modified: April 23, 2026
Vendor: Cisco
Source: NVD

Description

Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.

CWE

CWE-119

Affected Products

cisco unified communications manager expresscisco ios

References