Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-0332


A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms in the software. An attacker could exploit this vulnerability by sending high volumes of SIP INVITE traffic to the targeted device. Successful exploitation could allow the attacker to cause a disruption of services on the targeted IP phone. Cisco Bug IDs: CSCve10064, CSCve14617, CSCve14638, CSCve14683, CSCve20812, CSCve20926, CSCve20945.


Published

2018-06-07T21:29:00.400

Last Modified

2024-11-21T03:37:59.870

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-399
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco unified_ip_phone_firmware 9.9\(9.99002.1\) Yes
Hardware cisco unified_ip_phone_9951 - No
Hardware cisco unified_ip_phone_9971 - No
Operating System cisco unified_ip_phone_firmware 9.9\(9.99002.1\) Yes
Hardware cisco unified_ip_phone_7906g - No
Hardware cisco unified_ip_phone_7911g - No
Hardware cisco unified_ip_phone_7912g - No
Hardware cisco unified_ip_phone_7931g - No
Hardware cisco unified_ip_phone_7940g - No
Hardware cisco unified_ip_phone_7941g - No
Hardware cisco unified_ip_phone_7942g - No
Hardware cisco unified_ip_phone_7945g - No
Hardware cisco unified_ip_phone_7960g - No
Hardware cisco unified_ip_phone_7961g - No
Hardware cisco unified_ip_phone_7962g - No
Hardware cisco unified_ip_phone_7965g - No
Hardware cisco unified_ip_phone_7975g - No
Operating System cisco ip_phone_firmware 9.4\(2\)sr3.1 Yes
Hardware cisco ip_phone_7811 - No
Hardware cisco ip_phone_7821 - No
Hardware cisco ip_phone_7841 - No
Hardware cisco ip_phone_7861 - No
Operating System cisco ip_phone_firmware 9.4\(2\)sr3.1 Yes
Hardware cisco ip_phone_8811 - No
Hardware cisco ip_phone_8841 - No
Hardware cisco ip_phone_8845 - No
Hardware cisco ip_phone_8851 - No
Hardware cisco ip_phone_8861 - No
Hardware cisco ip_phone_8865 - No
Operating System cisco ip_phone_firmware 9.4\(2\)sr4 Yes
Hardware cisco ip_phone_8811 - No
Hardware cisco ip_phone_8841 - No
Hardware cisco ip_phone_8845 - No
Hardware cisco ip_phone_8851 - No
Hardware cisco ip_phone_8861 - No
Hardware cisco ip_phone_8865 - No

References