🔐 CVE Alert

CVE-2009-20005

UNKNOWN 0.0

InterSystems Caché UtilConfigHome.csp Stack Buffer Overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems Caché 2009.1. The vulnerability is triggered by sending a specially crafted HTTP GET request containing an oversized argument to the .csp handler. Due to insufficient bounds checking, the input overflows a stack buffer, allowing an attacker to overwrite control structures and execute arbitrary code. It is unknown if this vulnerability was patched and an affected version range remains undefined.

CWE CWE-121
Vendor intersystems corporation
Product intersystems caché
Published Sep 16, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for intersystems corporation intersystems caché

Be the first to know when new unknown vulnerabilities affecting intersystems corporation intersystems caché are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

InterSystems Corporation / InterSystems Caché
* ≤ 2009.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/http/intersystems_cache.rb exploit-db.com: https://www.exploit-db.com/exploits/16807 juniper.net: https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.APP:INTERSYSTEMS-CACHE-OF.html intersystems.com: https://www.intersystems.com/products/cache/ vulncheck.com: https://www.vulncheck.com/advisories/intersystems-cache-stack-buffer-overflow

Credits

MC