CVE-2006-4032
Summary
| CVE | CVE-2006-4032 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-09 22:04:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Callmanager Express | 3.0 | All | All | All |
| Hardware | Cisco | Callmanager Express | 3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| SecurityTracker.com Archives - Cisco CallManager Express Lets Remote Users Determine SIP User Names | SECTRACK | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| 27760 | OSVDB | www.osvdb.org | |
| Cisco - Global Home Page | CISCO | www.cisco.com | Vendor Advisory |
| Black Hat USA 2006 Topics and Speakers | MISC | www.blackhat.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Cisco CallManager Express SIP User Directory Disclosure - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.