CVE-2012-5445: Cisco Skinny Client Control Protocol Software

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.

Affected products

  • Cisco Skinny Client Control Protocol Software: up to and including 9.2\(4\); version 1.0(1) only; version 1.0(2) only; version 1.0(3) only; version 1.0(4) only; version 1.0(5) only; …
  • Cisco Unified IP Phone
  • Cisco Unified IP Phone 7906g

Published 2012-12-28. Last modified 2026-06-16.