{"api_version":"1","generated_at":"2026-07-23T08:49:43+00:00","cve":"CVE-2006-4032","urls":{"html":"https://cve.report/CVE-2006-4032","api":"https://cve.report/api/cve/CVE-2006-4032.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4032","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4032"},"summary":{"title":"CVE-2006-4032","description":"Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-08-09 22:04:00","updated_at":"2017-07-20 01:32:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/19309","name":"19309","refsource":"BID","tags":[],"title":"Cisco CallManager Express SIP User Directory Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1016627","name":"1016627","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - Cisco CallManager Express Lets Remote Users Determine SIP User Names","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3126","name":"ADV-2006-3126","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27760","name":"27760","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.cisco.com/warp/public/707/cisco-sr-20060802-sip.shtml","name":"20060802 SIP User Directory Information Disclosure","refsource":"CISCO","tags":["Vendor Advisory"],"title":"Cisco - Global Home Page","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.blackhat.com/html/bh-usa-06/bh-usa-06-speakers.html#Endler","name":"http://www.blackhat.com/html/bh-usa-06/bh-usa-06-speakers.html#Endler","refsource":"MISC","tags":[],"title":"Black Hat USA 2006 Topics and Speakers","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28185","name":"cisco-callmanager-sip-information-disclosure(28185)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21335","name":"21335","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Cisco CallManager Express SIP User Directory Disclosure - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4032","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4032","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4032","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"callmanager_express","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4032","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"cisco","cpe5":"callmanager_express","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4032","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20060802 SIP User Directory Information Disclosure","refsource":"CISCO","url":"http://www.cisco.com/warp/public/707/cisco-sr-20060802-sip.shtml"},{"name":"21335","refsource":"SECUNIA","url":"http://secunia.com/advisories/21335"},{"name":"cisco-callmanager-sip-information-disclosure(28185)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28185"},{"name":"1016627","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016627"},{"name":"19309","refsource":"BID","url":"http://www.securityfocus.com/bid/19309"},{"name":"27760","refsource":"OSVDB","url":"http://www.osvdb.org/27760"},{"name":"ADV-2006-3126","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3126"},{"name":"http://www.blackhat.com/html/bh-usa-06/bh-usa-06-speakers.html#Endler","refsource":"MISC","url":"http://www.blackhat.com/html/bh-usa-06/bh-usa-06-speakers.html#Endler"}]}},"nvd":{"publishedDate":"2006-08-09 22:04:00","lastModifiedDate":"2017-07-20 01:32:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:h:cisco:callmanager_express:3.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4032","Ordinal":"19358","Title":"CVE-2006-4032","CVE":"CVE-2006-4032","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4032","Ordinal":"1","NoteData":"Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4032","Ordinal":"2","NoteData":"2006-08-09","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4032","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}