CVE-2008-0529

CRITICAL

Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code vi...

Affects 5 products across 1 vendor.

BCS7.83
CVSS 2.010.0
EPSS5.4%
Percentile92th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-119: Improper Restriction of Operations within Memory Buffer

Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-119
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-119
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-119
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-119
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-119
Show all 12

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2008. A critical vulnerability affects Cisco systems (CVE-2008-0529). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2008-GLOBAL-020250-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-0529?
This vulnerability was disclosed in 2008. A critical vulnerability affects Cisco systems (CVE-2008-0529). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2008-0529?
CVE-2008-0529 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 5.4%.
Is CVE-2008-0529 actively exploited?
No confirmed active exploitation of CVE-2008-0529 as of 2026-05-30.
How do I remediate CVE-2008-0529?
Priority: MEDIUM. Advisory: http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7a.shtml PSIRT: [email protected]
What systems are affected by CVE-2008-0529?
CVE-2008-0529 affects: Cisco, Cisco, Cisco, Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2008-0529
BSIDBS-2008-GLOBAL-020250-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2008-02-15
Last Modified2026-04-23
ICS Relevance90%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Unified Ip Phone
Cisco Skinny Client Control Protocol \(Sccp\) Firmware
Cisco Session Initiation Protocol \(Sip\) Firmware
Cisco Session Initiation Protocol (Sip) Firmware
Cisco Skinny Client Control Protocol (Sccp) Firmware
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 6745 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash799d0aeab9cbc8506991db2934b83c63c7e55139882a6935eac29f1ded88b7e7a30a31661e8c026bd22c83fc7e26415fc2a21903a2ceed46a220871b8afad63e
Related CVEs affecting Cisco
CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2003-1096 10.0 The Cisco LEAP challenge/response authentication mechanism uses passwords in ... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un... CVE-2004-1760 10.0 The default installation of Cisco voice products, when running the IBM Direct... CVE-2000-1055 10.0 Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote at...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →