Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-1635


A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability is due to incomplete error handling when XML data within a SIP packet is parsed. An attacker could exploit this vulnerability by sending a SIP packet that contains a malicious XML payload to an affected phone. A successful exploit could allow the attacker to cause the affected phone to reload unexpectedly, resulting in a temporary DoS condition.


Published

2019-05-03T15:29:00.713

Last Modified

2024-11-21T04:36:58.740

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-399
  • Type: Primary
    CWE-755

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ip_conference_phone_7832_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_conference_phone_7832_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_conference_phone_7832_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_conference_phone_7832_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_conference_phone_7832 - No
Operating System cisco ip_conference_phone_8832_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_conference_phone_8832_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_conference_phone_8832_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_conference_phone_8832_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_conference_phone_8832 - No
Operating System cisco ip_phone_7811_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_7811_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_7811_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_7811_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_7811 - No
Operating System cisco ip_phone_7821_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_7821_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_7821_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_7821_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_7821 - No
Operating System cisco ip_phone_7841_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_7841_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_7841_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_7841_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_7841 - No
Operating System cisco ip_phone_7861_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_7861_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_7861_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_7861_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_7861 - No
Operating System cisco ip_phone_8811_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_8811_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_8811_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_8811_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_8811 - No
Operating System cisco ip_phone_8841_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_8841_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_8841_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_8841_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_8841 - No
Operating System cisco ip_phone_8845_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_8845_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_8845_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_8845_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_8845 - No
Operating System cisco ip_phone_8851_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_8851_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_8851_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_8851_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_8851 - No
Operating System cisco ip_phone_8861_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_8861_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_8861_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_8861_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_8861 - No
Operating System cisco ip_phone_8865_firmware 9.3\(4\)sr3 Yes
Operating System cisco ip_phone_8865_firmware 10.3\(1\)sr4b Yes
Operating System cisco ip_phone_8865_firmware 11.0\(4\)sr2 Yes
Operating System cisco ip_phone_8865_firmware 12.1\(1\)sr1 Yes
Hardware cisco ip_phone_8865 - No
Operating System cisco unified_ip_8831_conference_phone1_firmware 9.3\(4\)sr3 Yes
Operating System cisco unified_ip_8831_conference_phone1_firmware 10.3\(1\)sr4b Yes
Operating System cisco unified_ip_8831_conference_phone1_firmware 11.0\(4\)sr2 Yes
Operating System cisco unified_ip_8831_conference_phone1_firmware 12.1\(1\)sr1 Yes
Hardware cisco unified_ip_8831_conference_phone1 - No
Operating System cisco unified_ip_8831_conference_phone_for_third-party_call_control2_firmware 9.3\(4\)sr3 Yes
Operating System cisco unified_ip_8831_conference_phone_for_third-party_call_control2_firmware 10.3\(1\)sr4b Yes
Operating System cisco unified_ip_8831_conference_phone_for_third-party_call_control2_firmware 11.0\(4\)sr2 Yes
Operating System cisco unified_ip_8831_conference_phone_for_third-party_call_control2_firmware 12.1\(1\)sr1 Yes
Hardware cisco unified_ip_8831_conference_phone_for_third-party_call_control2 - No
Operating System cisco wireless_ip_phone_8821_firmware 9.3\(4\)sr3 Yes
Operating System cisco wireless_ip_phone_8821_firmware 10.3\(1\)sr4b Yes
Operating System cisco wireless_ip_phone_8821_firmware 11.0\(4\)sr2 Yes
Operating System cisco wireless_ip_phone_8821_firmware 12.1\(1\)sr1 Yes
Hardware cisco wireless_ip_phone_8821 - No
Operating System cisco wireless_ip_phone_8821-ex_firmware 9.3\(4\)sr3 Yes
Operating System cisco wireless_ip_phone_8821-ex_firmware 10.3\(1\)sr4b Yes
Operating System cisco wireless_ip_phone_8821-ex_firmware 11.0\(4\)sr2 Yes
Operating System cisco wireless_ip_phone_8821-ex_firmware 12.1\(1\)sr1 Yes
Hardware cisco wireless_ip_phone_8821-ex - No

References