CVE Database
/

CVE-2017-6624

Back to search

CVE-2017-6624

Published: May 3, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections component of the affected software. An attacker could exploit this vulnerability to place unauthorized, long-distance phone calls by using an affected system. Cisco Bug IDs: CSCuy40939.

VendorProductVersions

n/a

Cisco CallManager Express

affected
Cisco CallManager Express

Weaknesses (CWE)

References

98283
vdb-entry
x_refsource_BID
1038398
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now