← Vulnerability feed

Vulnerability record · CVE-2008-0027 · published 17 January 2008

CVE-2008-0027: Cisco Unified Communications Manager CTL Provider heap buffer overflow

Cisco · Unified Callmanager

The Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager and CallManager contains a heap-based buffer overflow triggered by a long request. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the affected system.

10.0 CVSS 2.0 High EPSS 57% · top 1.0% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, combined with a high EPSS percentile, warrants critical priority despite the absence of KEV listing.

What it is

The Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager and CallManager contains a heap-based buffer overflow triggered by a long request. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the affected system.

Impact

An attacker can cause a denial of service against the CTL Provider service or execute arbitrary code with the privileges of that service, which could lead to full compromise of the host.

Attack surface

The flaw is reachable over the network via the CTL Provider service listening on the affected CUCM/CallManager systems; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

The record is not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is high (0.571, 99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the Cisco vendor patch referenced in the advisory (CUCM 4.2(3)SR3, 4.3(1)SR1, CallManager 4.1(3)SR5c or later).
  • Restrict network access to the CTL Provider service (TCP 2444) to trusted management hosts only.
  • Segment or firewall CUCM management interfaces away from untrusted networks.
  • Monitor for and investigate unexpected crashes or restarts of CTLProvider.exe.
  • If patching is delayed, disable the CTL Provider service where operationally feasible.

Detection

  • Monitor CTLProvider.exe process crashes or service restarts on CUCM hosts.
  • Alert on anomalous or oversized requests to the CTL Provider service port from untrusted sources.
  • Review network logs for scanning or connection attempts to the CTL Provider service from external addresses.
  • Correlate host and network telemetry for signs of code execution following a CTL Provider crash.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0027 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-20045Cisco Unified Communications products HTTP input code injection RCECisco Unified CM, Unified CM SME, IM & Presence, Unity Connection, and Webex Calling Dedicated Instance fail to properly validate user-supplied input…KEVEPSS 4.5%analysed8.6CVE-2026-20230Cisco Unified CM SSRF enables file write and root escalationCisco Unified Communications Manager and Unified CM SME fail to properly validate input for specific HTTP requests, allowing server-side request forg…KEVEPSS 88%analysed10.0CVE-2025-20309Cisco unified communications manager hard-coded credentials vulnerabilityA vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …EPSS 1.1%10.0CVE-2024-20253Cisco unified communications manager deserialization of untrusted data vulnerabilityA vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to exe…EPSS 2.4%10.0CVE-2011-1643Cisco unified communications manager information exposure vulnerabilityCisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Pre…EPSS 1.9%10.0CVE-2008-1154Cisco emergency responder improper authentication vulnerabilityThe Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and…EPSS 5.1%10.0CVE-2007-5538Cisco unified callmanager memory buffer overflow vulnerabilityBuffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), …EPSS 5.5%

Source: NIST National Vulnerability Database (record CVE-2008-0027), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.