← Vulnerability feed

Vulnerability record · CVE-2012-5445 · published 28 December 2012

CVE-2012-5445: Cisco skinny client control protocol software improper input validation vulnerability

Cisco · Skinny Client Control Protocol Software

The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.

6.8 CVSS 2.0 Medium EPSS 0.40% · top 68.4% CWE-20 · Improper input validation
6.8CVSS 2.0 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.

AV:L/AC:L/Au:S/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-5445 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.6CVE-2011-1602Cisco unified ip phone 7906 permissions and access controls vulnerabilityThe su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecif…EPSS 0.26%6.6CVE-2011-1603Cisco unified ip phone 7906 permissions and access controls vulnerabilityCisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bu…EPSS 0.26%6.4CVE-2002-0882Cisco voip phone cp-7940 vulnerabilityThe web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read s…EPSS 2.7%6.1CVE-2018-15434Cisco skinny client control protocol software cross-site scripting vulnerabilityA vulnerability in the web-based management interface of Cisco Unified IP Phone 7900 Series could allow an unauthenticated, remote attacker to conduc…EPSS 0.92%5.0CVE-2002-0880Cisco voip phone cp-7940 vulnerabilityCisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated b…EPSS 1.3%4.6CVE-2012-1328Cisco unified ip phone code injection vulnerabilityCisco Unified IP Phones 9900 series devices with firmware 9.1 and 9.2 do not properly handle downloads of configuration information to an RT phone, w…EPSS 0.41%3.5CVE-2007-6190Cisco unified ip phone information exposure vulnerabilityThe HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones asso…EPSS 1.0%2.1CVE-2002-0881Cisco voip phone cp-7940 vulnerabilityCisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to …EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2012-5445), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.