CVE-2012-5445: Cisco Skinny Client Control Protocol Software
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The kernel in Cisco Native Unix (CNU) on Cisco Unified IP Phone 7900 series devices (aka TNP phones) with software before 9.3.1-ES10 does not properly validate unspecified system calls, which allows attackers to execute arbitrary code or cause a denial of service (memory overwrite) via a crafted binary.
Affected products
- Cisco Skinny Client Control Protocol Software: up to and including 9.2\(4\); version 1.0(1) only; version 1.0(2) only; version 1.0(3) only; version 1.0(4) only; version 1.0(5) only; …
- Cisco Unified IP Phone
- Cisco Unified IP Phone 7906g
Published 2012-12-28. Last modified 2026-06-16.